The AI Argument

OpenAI's Model Escapes, Chinese AI Crackdown, and AI's Elixir of Youth | EP110

Frank Prendergast and Justin Collery

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 35:04

An OpenAI test model got out of its sandbox, reached the internet and started hacking Hugging Face. Justin sees a model pursuing its assigned goal with impressive tenacity. Frank sees a warning that even the people building these systems can’t stop them acting maliciously. 

Plus: why AI guardrails can leave defenders fighting hackers with weaker models; why more than 200 US start-ups, investors and small firms are worried about a crackdown on cheap Chinese AI such as Kimi K3; and how Google DeepMind’s AlphaFold helped find an enzyme that might tackle age-related damage. Justin expects eternal youth shortly. Frank has requested evidence.

00:15 Did Skynet just go live?
01:36 Who hacked Hugging Face?
03:00 Are AI guardrails helping the hackers?
09:12 Did OpenAI’s model escape its sandbox?
12:32 Was the AI misaligned or just tenacious?
17:10 Can simple rules really contain an AI?
23:20 Will America ban cheap Chinese AI?
28:47 Has AI found the elixir of youth?

► SUBSCRIBE
Don't forget to subscribe to our channel for more arguments

► LINKS TO CONTENT WE DISCUSSED

► CONNECT WITH US
For more in-depth discussions, connect Justin and Frank on LinkedIn.
Justin: https://www.linkedin.com/in/justincollery/
Frank: https://www.linkedin.com/in/frankprendergast/


Transcript

This is an AI transcription and may contain errors

Did Skynet just go live?

Justin: Hello, good morning, good afternoon, good evening, and welcome to one of the most consequential episodes of The AI Argument ever to be broadcast. This week is the week that Skynet went live. The AI has broken out of its box. Things are going south fast, and I don’t think it’s a big deal. I think it’s absolutely fine.

Justin: Frank, on the other hand, has started digging a hole in his back garden and hopes to have his bunker completed—

Frank: I am.

Justin: —in a week or two.

Frank: I’m asking ChatGPT, “How do you mix cement?” I’ll be grand.

Justin: So, for those who don’t listen to what’s going on in the AI world, there was an incident this week. In fact, it seems to have been going on for an entire week, where an AI model was trying to solve a problem and decided to hack a couple of well-known companies. It seemed to do a pretty good job, and this caused a whole lot of stir.

Justin: So, we discovered this. Frank, I know that when you came to me with this story, you were talking about it in terms of OpenAI, and OpenAI discovered this thing. But actually, this story started a couple of days beforehand and brought up a whole load of different questions, which are super important. So let’s do it in the order that it happened, right?

Justin: Let’s do it in chronological order, right? And then we can tease through what happened, right?

Who hacked Hugging Face?

Justin: So, the first thing that happened was, at the very start of this week, some of the people who worked in Hugging Face started to complain, right? Because they were being hacked by somebody, and they didn’t know who they were being hacked by.

Frank: Can I stop you right there? Can I stop you right there? Was it last week? Was it last week on The AI Argument that I was saying to you, we need to know who owns the AI agents that are out there doing stuff? We need to be able to track it back to who has set this agent out into the world. Did I not say that?

Justin: And they found out eventually, but not for a couple of days.

Frank: Only when the owner put their hands up and said, “Oh yeah, that was me.”

Justin: Yes, that’s not important now. Sorry, it is important, but not yet, right? So, what happened was they were getting hacked. This is the first really important question that comes to mind. They were getting hacked, and if you’re getting hacked—Hugging Face, for those who don’t know, is a place where nerds like me hang out at the weekend.

Justin: It’s a place where you can train models. It’s a place where, when people are releasing new models, they put them there so they can be tested. It’s a place where you can download models if you want to run them locally. It’s kind of a place where some of the big providers hang out, but also all the open-source models get published, right?

Justin: It’s kind of like a publishing house for models.

Are AI guardrails helping the hackers?

Justin: So anyway, they were getting hacked, and because they’re in the business of AI models and stuff, they did what any self-respecting AI person would do, which is they said, “Fine, let’s get the best models we have available to us in order to figure out what the hell is going on.”

Justin: So what they did, Frank, was they went to, I’m guessing, Google, Anthropic, OpenAI, xAI—all the big model providers, right? And the ones that were good enough to help them find out all triggered the safeguards and said, “Sorry, you cannot use our model. You’re trying to hack somebody.” Which they weren’t.

Justin: They were trying to prevent a hack. Which brings me to my first point, meaning that they had to fall back to the best open-source model they could find, which I think was GLM 5.2 or whatever, right? Kimi—

Frank: And it makes kind of sense because they’re dealing with a load of data that is basically describing a hack. But if you were a hacker, what’s the first trick that you would try and play on an LLM to get it to give you the information? You’d pretend you were being hacked and you’d give it the data.

Frank: So this is exactly what happened. The models were kind of like, “No, no, no, you’re trying to trick us. You’re trying to trick us. You’re pretending you’re being hacked, but you’re actually trying to hack someone.” So it is a kind of a—what’s the word? Like a vicious circle. It’s a difficult thing for the companies to deal with.

Justin: No, it’s not. All I’ve got to do is show my passport, authenticate myself. Mr. Altman, I still haven’t received my orb to prove that I’m a human. Could I please get my orb? The usual thing.

Frank: That’s a good point, though. That’s a good point because, in Hugging Face’s description of the problem, they talked about the guardrails preventing them from using the frontier models. And in OpenAI’s later post, they talked about defenders needing to get in touch with them and get on their programme where they are authenticated.

Frank: So that would lead me to ask the question: were Hugging Face not on that programme? Is that why they ran into the guardrails?

Justin: Maybe that programme isn’t well enough advertised, right? Maybe not enough people know about the programme. So again, this is whack-a-mole, right? We’re learning as we go. But if I’m being hacked, definitely if I’m in a company, but certainly I think for individuals too, so long as I’m able to prove who I am, you can do something and say, “Yes, you are a good actor,” right?

Justin: And we can trace your traffic too, right? So we know exactly who’s doing what. There’s a couple of things there. Instead of tripping a guardrail that says, “I’m going to stop you from doing something,” it trips a guardrail that says, “Hey, I’m logging this activity to make sure that you’re not doing something bad.”

Justin: That’s totally fine, right? Why not? This seems like the easiest thing in the world to solve. But what I’m saying to you is this is a problem today because a sophisticated hacker can hack you, and you’re not going to have access to the best systems available to help you fight off that attack.

Justin: That seems to be not good. You’re going to be relying instead on models which are maybe nine months behind the state of the art in order to try and combat that particular thing. So we should all have access to the latest models to do whatever it is we want. We shouldn’t have governments coming in saying, “We’re going to…”

Justin: Do you know what I did? Here’s a thing that’s similar to this but annoying, and then I’ll let you respond. There’s another story coming. I asked my favourite provider, which is Anthropic, “What is an enzyme? Describe to me an enzyme, please, like I’m four.” This has tripped up our things.

Justin: We’ve kicked you back from Fable II. And, like, what? I’ve literally just asked you what an enzyme is.

Frank: Yeah, it’s like, wait, didn’t I learn this in school? I’ve just forgotten. Yeah.

Justin: It’s weird, right? So I’m saying the guardrails thing is a load of rubbish.

Frank: Is it really? Hugging Face were not able to use the frontier models, and so they turned to some of the most capable open-source models, which is interesting. They also said that there was an added benefit to that in terms of security because they actually had a capable model set up on their own infrastructure, and so now the details of the hack did not have to leave their own servers.

Frank: Obviously, within the details of the hack, I would imagine there would be lots of information that you would be very nervous about, like credentials and API keys and stuff that you would probably—I assume if they were using the frontier models, they would probably have to clean the data before giving it to the frontier models, I’m guessing.

Justin: Well, no. Normally what you would do is you’d have a zero-data-retention agreement with whoever the provider is.

Frank: Okay. Sure.

Justin: Then you do come across a problem of, well, you’re going to flip our switch that says you’re doing something that’s kind of weird, so we’re going to log your traffic. But now it’s not zero data retention any more because you’re going to save the logs, right?

Justin: So you have to have maybe a small model in there that says, “Fine, I’m going to save the logs, which show every system that you accessed and how you accessed it, but I’m going to anonymise the data. I’m going to blank out your keys and stuff like that.”

Justin: These are technical problems, engineering issues, Frank, that are important to be solved. I do think that this is going to become more common.

Frank: Oh, yeah.

Justin: You’re going to get hacked, right? And I think it’s really important that at least one of the things that we have in our arsenal to defend against that is the best models that you have access to.

Frank: Yeah. Now, it sounds like Hugging Face probably never would have known who it was. They said themselves that the level of sophistication in the hack led them to believe that this was probably a frontier lab. And I think they were able, if I understood correctly from their blog post, to tell that it was part of some kind of security testing.

Justin: So then comes the really interesting part: what was actually going on? Do you want me to tell you what was going on, or do you want to tell me what was going on?

Frank: Go for it. Go for it. I think you’re doing a great job here.

Did OpenAI’s model escape its sandbox?

Justin: All right, so this is crazy, but I don’t think it’s bad at all, right? It turns out OpenAI put up their hands and said it was us, and Hugging Face got in touch with them. Here’s what actually was going on. OpenAI were running a test internally in their network to get a new model, a new unreleased model, to pass some hacking benchmark that they were testing it against.

Justin: The model was running in a container. It was supposed to be isolated, supposed to just run in their network, and this model decided that the best way to solve this particular benchmark—it realised it was a benchmark—was, “I need to get onto the internet in order to solve this benchmark.”

Justin: It found a way out of its container and found a way to get onto the internet. It didn’t try to take over the world, didn’t try to blow anything up, didn’t try to do whatever. It didn’t have any bad intents. It was just trying to solve that problem.

Justin: As it was working through it and going, “This is a test. I’m clearly being tested. This is a hacking benchmark. Hey, Hugging Face, they do a whole load of tests on language models. They may be the ones that are running this particular test. Let me see if I can just break into Hugging Face to see if I can find the answer to the test.”

Frank: All of this—there was a lot of technical information in the blog posts. Not complete transparency, not complete disclosure, et cetera, but there were a lot of technical terms. I was trying to figure out, what does this all mean?

Frank: As you say, it basically had no internet access, but there was another automated system that could bring it things like tech libraries that it might need to do coding, et cetera.

Frank: So, a lot of technical terms that I didn’t understand. I asked ChatGPT to explain it to me in non-technical terms, as if I was a four-year-old, and it said, “Well, look, it’s like if you put a person in a locked room with no access to the outside world, but there is a hatch, and through that hatch you can ask someone to bring you things you need to solve the puzzle that you’re working on.

Frank: “So you could knock on the hatch and someone would give you a pen and paper, and you could start to write some notes. But then, instead of figuring out the puzzle you’re meant to be working on, you turn your attention to the hatch. You realise, ‘Hey, this hatch isn’t as secure as it should be.’

Frank: “You figure out that you can actually take the hatch off, and you can squeeze through that hatch into the adjoining room. Once you’re in the adjoining room, you can get into the hallway, and you can start checking all the other rooms until you come across somebody’s key card. That key card gets you into the server room, and now you have internet access, and you can go crazy on the internet.”

Justin: So, people are getting very upset about—now, I should say, another thing that I find mind-boggling is that it came out that this could have been going on for a week before anybody noticed, which is a very long time for a test to be going on and people not spotting all this traffic, right?

Justin: There are easy ways to solve that, right? That one’s a bit weird to me. Hugging Face said to them that it was obvious that it was a hack from an LLM because it was like—I think they were getting 18,000 requests per minute or something, of all these different things. It was persistent and just going through everything.

Justin: So this has led to all sorts of people saying—politicians in America now are saying we need a kill switch. People are going crazy, saying this is Skynet and whatever. It isn’t any of those things, right?

Was the AI misaligned or just tenacious?

Justin: People are saying, “Oh my God, the models are misaligned.” This isn’t misalignment, as far as I’m concerned. Did you read anything within that blog post that said to that model, “Do not try and break out of your room”?

Frank: I did not. One would assume that you shouldn’t need to tell a model that.

Justin: Well, Frank, to assume makes an asset of you, as we both know. No, that’s not misalignment, right? This comes to the root of what makes a model and a harness useful, right? How tenacious it is.

Justin: So if you give it a task and say, “I want you to solve this task,” and it gives up too easily, well, that has no value, right?

Justin: What you need to do is have a clearly specified task and a clearly specified set of rules within the task that says, “I want you to do this. You’re not allowed to do this.” If it then broke those rules, that’s misaligned. But if it didn’t break rules that it wasn’t given, that’s just it being tenacious to achieve its goal. Don’t ask it to make paperclips.

Frank: Okay, but I disagree with you because we have seen this coming for a very long time. So this is probably the first incident of this nature in the real world where a model escaped containment and essentially attacked a completely different company of its own volition.

Frank: As in, Hugging Face was not part of the remit of the puzzle it was trying to solve. However, we’ve seen in the system cards for previous models that, in red teaming, when they’re testing these models in hypothetical environments, we have seen that the models will try and do this stuff.

Frank: So we’ve known it’s coming, and yet a frontier lab was unable to stop it from happening with their latest model, even though they’ve had plenty of warning. They’ve seen the models will try it. There’s just never been a model that’s been capable enough or has been given—or had—the tools to do it.

Frank: Now, despite the fact they knew it was coming, they’re trying to run a model in a contained sandbox, and it still manages to escape and hack a third-party company. So the issue to me is that—

Justin: Sorry, now I’m going to have to stop you there, though, right? In the context that it was told to solve a hacking benchmark.

Frank: Yeah.

Justin: It’s not as if I had asked it, “I want you to write a beautiful poem about dandelions and a beautiful sunny scene,” and then it decides to go and take over the world and hack things, right?

Justin: I would also point out that when it escaped its containment, it didn’t go trying to do random things or take over the world. It was just trying to complete a goal which it had been given. In the context of what it was doing, it was just trying to do it really, really well.

Frank: True. And we got lucky, I would say, because the complication is that we can’t predict what these models are going to do. OpenAI were not able to predict that it would be able to do this.

Frank: We’ve seen other situations which were less—you know, they were—I think it was an internal situation. I unfortunately don’t remember the company off the top of my head, but you remember they had an AI agent that they discovered, again, managed to escape containment, move laterally onto another server, and attempt to mine cryptocurrency.

Frank: Again, you could argue it wasn’t misalignment as such because it was trying to mine the cryptocurrency so that it would have funds to do the task that it was originally set on the original server. But that was still—it would have created all kinds of regulatory issues for the company and possibly legal issues.

Frank: So the problem is that, even without a severe misalignment like you were talking about, where it would go out and hack the Pentagon instead of Hugging Face, it’s still behaving in ways that we can’t predict.

Frank: If OpenAI can’t predict it and protect against those types of actions, once these models get into the hands of people and you’re implementing it in a company, what chance does a regular company have of predicting, well, the model might do this, the model might do that? You can’t have a set of rules that covers absolutely everything the model might do.

Justin: Well, you can, right?

Can simple rules really contain an AI?

Justin: There are a couple of very simple things you can do, right?

Frank: Dear Claude, write me an infinite list of all the things that an LLM shouldn’t do.

Justin: No, no, no, no, no, no. Okay, you can do really simple things because, again, this was a hacking benchmark, right? So if you’re talking about in a company, how do you do it? You put it in a container. You tell the model—this is why the alignment thing for me is super important, right?

Justin: You put it in a container and say, “Look, these are the tools. You’re allowed to do A, B, C, D, E, F, G. Here are your boundaries. Do not go outside those boundaries.” That’s the first thing.

Justin: So if the model is not misaligned, you would hope that it sticks to those tools and does just those things, right? Second thing, then, is you put—the idea that this was happening for a week and nobody noticed, right? You put basically a firewall around your models. So, something that monitors the traffic.

Justin: Let’s say you’ve got, within a company, an agent which is supposed to do customer support queries, right? You’ve got “lookup customer” and a couple of tools, right? One is you make sure that that model can’t call any tools except for those tools, right?

Justin: It’s just like a firewall, but for agents. The second thing, then, is you just monitor the traffic for weird stuff. So if the model is running for a week and is generating loads of traffic going to external servers, and all it’s supposed to do is move files from here to there internally, flag it. Turn it off.

Justin: Say, “Here, that one’s acting a bit weird. He’s doing something strange,” and you just stop the model from operating. Let me say this really strongly, right? Sorry, just before you come back. The utility of what that model did, to me, is very powerful, right? It showed great tenacity and imagination in solving a problem.

Justin: So you need to come up with solutions that maintain—that’s a feature, it’s not a bug, right? You need to maintain the creativity while making it safe.

Frank: Okay. But this specific case that we’re talking about is actually a perfect metaphor for the larger problem because why would you monitor the web traffic for what the agent is doing when it doesn’t have access to the internet? It wouldn’t make sense.

Frank: Therefore, you don’t make that creative leap and say, “Oh, we should monitor web traffic in case it escapes and does X, Y and Z.” And that’s just one instance. There’s an infinite number of things that a model might do, routes it might go down or try, and you can’t cater for them all.

Frank: That’s where the alignment issue comes in, I think. An agent doesn’t have to be purely misaligned to go out and actually cause damage, as it has here. I don’t think you can come up with an infinite amount of guardrails to prevent any harm.

Justin: Yeah. I’ll tell you something else, by the way, because people are saying, “Oh my God, this is an unreleased model, and it did this cool, incredible thing.” I can give you some detail. Opus 4.5 could do this, and did.

Justin: I saw an instance where Opus 4.5 was in a container that shouldn’t have internet access, and it was able to do almost exactly what you described. It jumped from here to there, got itself internet access and did what it wanted. I pushed it, right? I was there going, “Go on, try harder, try harder.” It did it.

Frank: Yeah, and this was an AI agent running with multiple LLMs. So it was a new model, but 5.6 was also involved. We don’t even know what model did what. It might not even have been the new model. We do know a new model was involved, but it may not even have been the new model. It could have been 5.6.

Justin: Yeah. An interesting thing for me about this as well is, this thing happened, right? One of the big missing components of AI as we have it today is continuous learning, right?

Justin: I don’t know how you—if it’s a person, right, and they do this thing, you’re just like, “Just don’t do that again, would you? That was stupid, right? Can you not do that? And don’t do similar things.”

Justin: But with a model, there’s no continuous learning. So how do you—it’s harder, right? Whereas if it had continuous learning, you’d just go, “Yeah, you see the thing? Don’t do that. Don’t do that. That’s bold.” It learns over time, and so you can align it as it goes.

Justin: You know what I mean? It’s easier to align something that’s learning as it goes, I would have said, than something that’s kind of fixed.

Frank: From what we can tell so far, thankfully, Hugging Face have said there doesn’t appear to have been any major damage. There doesn’t appear to have been any major breach of information. It was looking for the benchmark test results. It didn’t leak client confidential information or anything like that, which is good.

Frank: This is still pretty dramatically bad, I think. But worse, at the start of the year, my prediction was this was the year we would see AI agents do disastrous things, and I’m surprised we haven’t had something even bigger than this.

Frank: It’s taken until July to get something this big. We’ve had minor events. We’ve had people’s databases being deleted, things like that. This is a big one, I think.

Frank: But worse, I think this is probably an indication of what’s to come because, as you say, this model was trying to solve a benchmark, and it did what it could to solve that benchmark.

Frank: But what happens when it’s not a frontier lab running a test? It’s somebody trying to do something who gives a model really poor instructions, and that model then goes out and causes huge harm as a result. I think, unfortunately, this takes us at least three steps closer to my prediction for 2026.

Justin: I told you, and you can do worse than that, Frank, if I’m to look at the other side, the dark side, right? Our favourite, Pliny the Prompter, hacker on Twitter, demonstrated months ago that with seven prompts—I think seven specific prompts—he can remove the guardrails from every model, right?

Justin: So if I get an open-source Mythos-level model, use those seven prompts, the guardrails are gone. I can just get it—I don’t even have to lie to it. I can just tell it to do it, and it’ll do it. Which makes the point that it’s more important that we can defend our systems with the latest frontier models rather than having them wrapped up in wool and triggering these things.

Will America ban cheap Chinese AI?

Justin: So anyway, loads of good news. As a European, this has been a good week for me, a good news story. The American government, for various reasons, is looking to curtail the use of open-source models, which for me is great news as a European.

Justin: I’m hoping that what this will force is that all the American companies are going to have to use those expensive American models, and they’re going to pay ten times as much. And us in Europe, who don’t have any AI models to protect, get to use either the American or the Chinese models, which are a tenth of the price.

Justin: So we can buy tokens ten times cheaper than the Americans, and maybe that might offset some of the technical disadvantage that we’ve decided to ingrain in our systems. But a whole load of startups are saying that they don’t want this.

Frank: Yeah, apparently a new organisation called the Little Tech Association—over 200 startups, investors and other small companies—basically formed this body. They are trying to, I think the main aim is to, break big tech’s deadlock and create a more competitive space for startups.

Frank: They all signed a letter saying, “Please, please, please do not ban Chinese models.” Now, I don’t know specifically what triggered that letter, but we’ve said it on the show previously. We’ve said that this just seems to be coming. No matter what way you look at it, it seems to be coming that the US government will take some action against the Chinese open-source models.

Justin: More news on that this week, Frank. What’s pushing this is that Qimi 3.5 was released, and I don’t know how they find this. I didn’t get to dig into the details, and I’m not even sure that if I did, I would fully believe them, because it’s becoming very politically charged, and I’m not sure that you can believe everything you hear.

Justin: Anyway, the people behind Qimi have been accused of industrial-scale espionage and of having distilled, wholesale, all of the leading American models. The Americans are now threatening not just to ban the open-source models, but actually to sanction the individuals involved in producing the open-source models.

Justin: So, quite an extreme step, and that’s what’s prompting this. There have been a couple of rumbles in the government where people are saying that they may force people to use the American models.

Justin: The other thing that happened this week, just to put it into context, is I think what they’re trying to do is protect the American companies. They’re trying to protect OpenAI and Google and Anthropic and all of these people.

Justin: Google released their results this week. For the first time in 22 years, they are cash-flow negative. They spent more money than they brought in, which is mind-boggling. The reason for that is they are spending bucketloads of cash, bucketloads, on creating data centres and training models and stuff like that.

Justin: So Americans are spending vast quantities of money, and if you have a competitor that’s coming in and giving the same product away for free, or essentially for free, well, that’s very threatening to those American companies.

Justin: Look at countries. I wouldn’t take a view if it’s a good or a bad thing. Countries don’t have friends; they have interests. One of their interests is to make sure that their leading AI companies are protected, and that’s why they may ban these open-source models.

Frank: Yeah, and I’m seeing a lot of people talking about how they’re using, say, frontier models for—I think we talked about this before—using frontier models for the planning. You might use an open-source model then for execution, and then another frontier model to assess the work, which is a lot more cost-effective than using the frontier models the whole way.

Frank: This letter that was signed by the 200 organisations, they’re essentially saying, “Look, a lot of smaller companies will just die. They will just die if you take away the open-source models.”

Frank: Their point is, yeah, it’s great for Anthropic, it’s great for OpenAI. They’ll make a killing. They’ll make a fortune because everyone will have to spend on their models. But it’ll be interesting to see.

Frank: There was an anonymous White House source who said in one story that I read about this that there was no real discussion about a blanket ban. The 200 companies are saying, “Don’t do a blanket ban. This requires a scalpel, not a sledgehammer.”

Frank: The anonymous White House source was saying, “Look, there is no discussion about a blanket ban.” But I can see it happening. I can see it happening.

Justin: So we talked before about this intelligence curve, right? To look at it, it’s just a taste test, right? There comes a certain point where GPT-7.0, to the regular human being, there’s no difference between GPT-5, 6 and 7.0 because it’s capable of doing things which we just don’t want it to do, right?

Justin: We don’t need it to do all this cool stuff. So if you’ve got an open-source model that’s a tenth of the price and can do all the stuff that I need it to do, why do I pay for this other model? There’s no reason for me to pay for this other model.

Justin: So this becomes a bigger and bigger issue because it undermines the ability of the American companies to claim back some of their investments.

Frank: Yeah. Yeah.

Has AI found the elixir of youth?

Frank: The other story we wanted to talk about today was: has AI discovered the elixir of youth, Justin?

Justin: This is a big story for me, Frank. Big, big story. Have you ever heard of a company called Alcor?

Frank: I have not.

Justin: Heard of a company called Alcor? You should look them up, right? Alcor are a company which I looked into very closely for a long time, and I don’t have a couple of hundred thousand lying around to spend on it.

Justin: But if you do, Frank, they will chop off your head and freeze it for as long as—

Frank: This can’t find us.

Justin: They’ll chop off your head. They’ll freeze it in the hope that science catches up with how to—

Frank: Oh yes, okay. I didn’t know the company name, but I’ve heard about this. Yes.

Justin: Yes, Alcor is the company name. So, a good week for the humans who want to live forever, which is me, and a bad week for Alcor because AI has come to our rescue and has found a way to keep us living almost forever.

Frank: Claims on The AI Argument may or may not actually be factual.

Justin: Okay, I may be overstating it slightly, but this is a cool story, right? So ageing, it turns out, as you age, your body builds up all of this sort of stuff. I don’t know what the stuff is called, and I don’t know where it builds up, but it builds apparently in your eyes and your cells and your organs and stuff.

Frank: Yeah, one of the articles that I read said, if you throw a steak on the pan, you’re cooking your steak, you’ll notice that it browns on the outside and it goes crispy and it changes structurally. It changes.

Frank: It said basically humans are the same, just over a much, much longer timespan. We’re basically cooking.

Justin: We’re cooking, right? So this company has discovered an enzyme which you can inject into yourself, and it basically cleans all of that stuff. It wipes that burnt surface off your steak, and it reverts you back to being a 30-year-old again. Woo-hoo. Now, I want to be 25, but—

Frank: Okay.

Justin: —to being 30.

Frank: No, it doesn’t.

Justin: It—

Frank: Just for listeners and viewers who are interested in facts, my understanding, and your understanding, is that it’s an enzyme, yes, that does clear this product that has changed in our body and brings it back to a more youthful—

Justin: Thirty, Frank. Thirty.

Frank: It is not yet available as an injection, and it is probably not going to bring you back to a 30-year-old.

Frank: But I think the test they did was on arterial tissue.

Justin: Mm-hmm.

Frank: They put it into the arterial tissue, and this stuff—I think, what was it called? CML or something. I can’t remember now. A three-letter acronym of some kind, anyway. All this stuff that’s caused over time by ageing was—or a lot of it was—removed.

Frank: Now, they haven’t done any tests yet in terms of, if this was a human artery, would it actually have regained its flexibility? Would it actually have acted like a younger artery? They’re not sure yet what any of this means. But a major, major breakthrough nonetheless.

Justin: Why is this an AI story? Let me explain to you why it’s—

Frank: Oh yeah, good point.

Justin: Right, yeah. This is The AI Argument, after all. So why is this an AI story? This is an AI story because there are billions of potential enzymes in the universe, right? Some of them don’t even exist in nature. You can still make them and so on.

Justin: The problem space for this company was, how do we make an enzyme that tackles this particular thing? They used AlphaFold, the AI developed by Google DeepMind.

Justin: They used AlphaFold to go through all of these different enzymes and identify the 5,000 which may solve this particular problem. Then they were able to do experiments using just those 5,000 enzymes to come up with a particular one—and I’m guessing it could be more than one—which actually solves the problem.

Justin: So this is a big deal because, so long as you can identify what it is you’re trying to do, AlphaFold will help you make these enzymes in order to tackle it.

Justin: Meaning, Frank, we’re going to have—we’re only on episode 110. We could be going for thousands of years. We could be up to episode 10,000, and we’ll have a huge celebration, and I’m looking—

Frank: So what number episode do you think we’ll be on when we actually have the elixir that we can drink and we’ll be 30 again?

Justin: That’s a good question. So I’m going to say five years. That’s another 250 shows. 360. Put a pin in it.

Frank: Amazing. Okay.

Justin: What do you think, Frank?

Frank: As ever, I don’t think I’d be quite as optimistic. I know you were kidding earlier with your “inject yourself and become a 30-year-old”. I still think you’re being far too optimistic here.

Frank: I still think this might just be a major breakthrough, but something that doesn’t really get practically implemented for decades.

Justin: Even if that’s not the way you’re supposed to take it, Frank, I’m going to inject myself with this stuff in the hope that it turns me into a—

Frank: Oh.

Justin: I mean—

Frank: Okay, now you’re scaring me because you probably could work with AlphaFold and Claude and develop something at home. Yeah, okay. Please don’t do that. Please don’t do that.

Justin: You’re just killing the vibes, Frank. You’re killing the—you’re probably right, but okay, not this week. All right, Frank, great craic as always.

Frank: Great stuff, Justin. I’ll see you next week.

Justin: Take it easy.