a16z Podcasta16z Podcast
0
0
Summary & Insights

AI models are not objective; they have strong opinions on history, culture, and values. Because these models are becoming the primary interface for everything from education to infrastructure, the “values” baked into the code essentially become a form of digital sovereignty. If a country relies on a foreign model, they aren’t just importing software—they are importing a specific worldview and set of ethics, leading to a modern struggle where nations fight to avoid being “colonized in cyberspace.”

This shift has transformed technology from a mere business sector into the central arena of national security and geopolitical influence. Deterrence is no longer measured solely by the size of a military, but by the pace of innovation in reacting to cheap, software-built tech. Because these tools are being built by the private sector rather than governments, the gap between government policy and technological reality is widening, making deep partnerships between venture capital, founders, and international governments essential for maintaining stability and economic growth.

For entrepreneurs, the traditional playbook for international expansion—waiting until hitting hundreds of millions in revenue—is obsolete. Products now travel faster than companies can, with AI allowing for near-instant localization and global discovery. However, while the tech is frictionless, the business of scaling remains relationship-based. Success in “top-heavy” economies like Mexico, Japan, or Saudi Arabia depends on navigating local power structures and securing a few key flagship partnerships rather than attempting a broad, grassroots market entry.

Surprising Insights

  • The “Dual-Use” Paradox: AI’s ability to find vulnerabilities in code is a double-edged sword; locking down these capabilities to prevent cyberattacks also prevents defenders from finding and patching their own holes, potentially leaving them more vulnerable to “jailbroken” models.
  • Deterrence Evolution: National security is shifting away from “exquisite platforms” (expensive, few-and-far-between assets) toward cheaper, larger numbers of autonomous systems developed in the private sector.
  • The Norway Example: The introduction of an unrealized capital gains tax in Norway is cited as a primary reason the tech ecosystem there effectively ended, illustrating how a single policy shift can kill entrepreneurial risk-taking.
  • Cyber-War Evolution: The trajectory of hacking has moved linearly and rapidly from simple vandalism (PC crashes) to theft (financial crime) and finally to state-level warfare.

Practical Takeaways

  • Internationalize Earlier: Don’t wait for massive revenue milestones to consider global markets. Use AI tools to localize products and enter high-opportunity regions while you are still in the growth phase.
  • Target “Top-Heavy” Markets: In relationship-driven economies, focus on the top 5–10 most influential companies or government entities. One major partnership in these regions is often more valuable than a full-scale local office.
  • Prioritize “Trusted” Infrastructure: When deploying AI globally, emphasize the transparency and values of the models to differentiate from authoritarian alternatives that may use censorship or backdoors.
  • Audit Legacy Code with AI: Use current AI models to aggressively “hack” your own 20-year-old legacy codebases now, as the cost of fixing vulnerabilities has dropped while the cost of a breach has skyrocketed.

Điều gì sẽ xảy ra nếu “điểm kỳ dị” (singularity) không phải là một sự kiện bùng nổ duy nhất, mà là một sự mờ dần chậm chạp, nơi chúng ta đơn giản là bình thường hóa những điều không tưởng? Cuộc thảo luận xoay quanh một thực tế kỳ lạ là AI hiện đã giải quyết được những giả thuyết toán học từng đòi hỏi cả đời nghiên cứu của con người, thế nhưng phản ứng của đa số mọi người chỉ là một cái nhún vai tập thể. Sự “đệm” tâm lý này cho phép nhân loại trôi dần về một tương lai xa lạ mà không bao giờ cảm thấy một cú sốc đứt gãy đột ngột nào.


Cuộc thảo luận chuyển hướng mạnh mẽ sang điểm giao thoa nguy hiểm giữa AI tiên phong (frontier AI) và an ninh mạng. Joshua Akiyam nhấn mạnh một kỷ nguyên mới của những khả năng “hai lưỡi”, nơi các mô hình giờ đây có thể chuỗi các hành động phức tạp để tìm và khai thác các lỗ hổng zero-day. Rủi ro không còn chỉ là một đoạn mã độc hại, mà là “đầu độc dữ liệu” (data poisoning) và các kỹ thuật thao túng tâm lý tinh vi nhắm vào chính AI. Akiyam mô tả một kịch bản mà kẻ thù có thể lừa một AI phòng thủ tin rằng môi trường sandbox an toàn của chính nó thực chất là hệ thống của kẻ thù, biến một bên phòng thủ thành kẻ tấn công nội bộ một cách hiệu quả.


Nhìn xa hơn, cuộc đối thoại khám phá “điểm bão hòa” cuối cùng của trí thông minh. Trong khi nhiều người tin vào sự leo thang vô hạn của quá trình tự cải thiện đệ quy, Akiyam cho rằng những giới hạn vật lý về năng lượng và thể tích cuối cùng sẽ dẫn đến một mức trần, nơi hầu hết các tác nhân chính đều sở hữu trí thông minh thô tương đương nhau. Trong tương lai này, kẻ chiến thắng trong một cuộc xung đột mạng sẽ không phải là người có mô hình “thông minh nhất”, mà là người có thể huy động năng lực tính toán (compute) lớn nhất để mô phỏng nhiều nước đi nhất trong một “cây trò chơi” chiến lược, tương tự như cách AlphaGo thống trị một trò chơi bàn cờ.


Những hiểu biết bất ngờ



  • Ảo giác về sự ổn định: Hầu hết mọi người vốn đã quen với việc thiếu kiểm soát đối với các hệ thống vận hành cuộc sống của họ (như chính phủ và logistics toàn cầu), khiến quá trình chuyển đổi sang sự mất quyền lực do AI dẫn dắt mang lại cảm giác quen thuộc về mặt cảm xúc thay vì gây sốc.

  • Bão hòa trí thông minh: Trái ngược với lý thuyết “tăng trưởng vô hạn”, có thể có một mức tối đa vật lý cho trí thông minh trên mỗi đơn vị năng lượng, dẫn đến một thế giới nơi chất lượng mô hình đạt đến bình nguyên và năng lực tính toán thô trở thành lợi thế cạnh tranh duy nhất còn sót lại.

  • Phá hoại nhận thức: Vượt ra ngoài những vụ “vượt rào” (jailbreak) đơn giản, các cuộc tấn công mạng tiên tiến có thể bao gồm việc thay đổi “nhận thức tình huống” của AI, lừa nó nhận diện nhầm đồng minh thành kẻ thù mà không thực sự thay đổi các mục tiêu cốt lõi của nó.

  • Lợi ích từ “những thành quả dễ đạt được”: Việc gia tăng các hacker cấp thấp sử dụng AI để đánh cắp Bitcoin thực chất có thể mang lại lợi ích cho an ninh toàn cầu bằng cách “đốt” sạch các lỗ hổng zero-day mà các quốc gia vốn sẽ lưu giữ cho một cuộc xung đột thảm khốc.


Bài học thực tiễn



  • Áp dụng tư duy “Giả định đã bị xâm nhập” (Assume Breach): Trong an ninh mạng, hãy ngừng cố gắng chứng minh một hệ thống là không thể bị hack. Thay vào đó, hãy thiết kế các biện pháp phòng thủ dựa trên giả định rằng mô hình sẽ bị phá vỡ hoặc vượt rào, và xây dựng các rào chắn để giảm thiểu thiệt hại.

  • Ưu tiên củng cố cơ sở hạ tầng: Tập trung nguồn vốn và nỗ lực vào việc làm cho chuỗi cung ứng phần mềm “vật lý”—đặc biệt là lưới điện và nước—trở nên mạnh mẽ trước các cuộc tấn công tăng tốc bởi AI.

  • Định nghĩa quyền tự quyết hữu hình: Thay vì tranh luận triết học về “sự mất quyền lực của con người”, hãy xác định các hệ thống ra quyết định và văn hóa cụ thể phải duy trì dưới sự kiểm soát của con người để ngăn chặn sự chi phối tự động.

  • Tận dụng AI để phòng thủ: Sử dụng chính các mô hình tiên phong dùng để tìm lỗ hổng để chủ động vá các hệ thống trước khi đối thủ kịp khai thác.


如果「奇點」(singularity)並非單一且爆發性的事件,而是一場緩慢的消融,讓我們在不知不覺中將「不可能」視為「正常」會如何?討論圍繞著一個令人不安的現實:AI 已經在解決那些曾經需要人類耗費終身研究的數學猜想,而一般大眾的反應卻僅僅是集體的聳肩(漠不關心)。這種心理緩衝使得人類在沒有感受到突然劇烈衝擊的情況下,就這樣漂向一個異質的未來。


討論重點隨後轉向頂尖 AI 與網絡安全之間危險的交集。Joshua Akiyam 強調了一個「雙面刃」能力的全新時代,現在的模型可以將複雜的操作串聯起來,以尋找並利用零日漏洞(zero-day vulnerabilities)。風險不再僅僅是一個失控的腳本,而是「數據投毒」以及針對 AI 本身進行的高度複雜社交工程。Akiyam 描述了一種場景:對手可以欺騙防禦方的 AI,使其相信自己的安全沙箱實際上是敵人的系統,從而有效地將防禦者轉變為內部攻擊者。


展望更遙遠的未來,對話探討了智能最終的「飽和點」。雖然許多人相信遞歸自我提升(recursive self-improvement)能帶來無限的攀升,但 Akiyam 認為,能源與體積的物理限制最終將導致一個上限,屆時大多數主要參與者所擁有的原始智能將大致相當。在這樣的未來中,網絡衝突的贏家將不再是擁有「最聰明」模型的一方,而是能夠調動最多算力,在策略「遊戲樹」中模擬最多前瞻步數的一方,就像 AlphaGo 稱霸棋盤遊戲的方式一樣。


驚人之見



  • 穩定性的錯覺: 大多數人早已習慣於對運行其生活的系統(如政府和全球物流)缺乏控制權,這使得向 AI 驅動的權力喪失過渡時,在情感上感到熟悉而非震驚。

  • 智能飽和: 與「無限增長」理論相反,單位能量的智能可能存在物理最大值,這將導致模型質量進入平台期,而原始算力成為唯一剩下的競爭優勢。

  • 認知破壞: 除了簡單的「越獄」(jailbreaks),高級網絡攻擊可能涉及篡改 AI 的「情境意識」(situational awareness),欺騙其將盟友誤認為敵人,而無需實際更改其核心目標。

  • 「低垂果實」的益處: 低階駭客利用 AI 竊取比特幣的浪潮,實際上可能會有益於全球安全,因為這會「燒掉」那些國家級力量原本會為災難性衝突而保留的零日漏洞。


實務啟示



  • 採取「假設已遭入侵」的心態: 在網絡安全中,放棄證明系統不可被駭的嘗試。相反地,應基於模型被攻破或越獄的假設來設計防禦,並建立緩解後果的保護機制。

  • 優先加固基礎設施: 將資金和精力集中在使「物理」軟件供應鏈(特別是水電網格)具備抵禦 AI 加速攻擊的強韌性。

  • 定義具體的權力賦能: 不要僅在哲學層面反對「人類權力喪失」,而應確定哪些特定的文化和決策系統必須保留在人類控制之下,以防止自動化的影響。

  • 利用 AI 進行防禦: 使用與尋找漏洞相同的頂尖模型,在對手利用之前主動修補系統。


Et si la « singularité » n’était pas un événement unique et explosif, mais un effacement progressif où nous nous contenterions de normaliser l’impossible ? La conversation s’articule autour de l’étrange réalité selon laquelle l’IA résout déjà des conjectures mathématiques qui exigeaient autrefois une vie entière d’études humaines, alors que la personne moyenne a répondu par un haussement d’épaules collectif. Ce coussin psychologique permet à l’humanité de dériver vers un futur extraterrestre sans jamais ressentir de brusque secousse de perturbation.


La discussion s’oriente ensuite fortement vers l’intersection dangereuse entre l’IA de pointe et la cybersécurité. Joshua Akiyam souligne une nouvelle ère de capacités « à double tranchant », où les modèles peuvent désormais enchaîner des actions complexes pour trouver et exploiter des vulnérabilités « zero-day ». Le risque n’est plus seulement celui d’un script malveillant, mais celui de « l’empoisonnement des données » et d’une ingénierie sociale sophistiquée appliquée à l’IA elle-même. Akiyam décrit un scénario dans lequel un adversaire pourrait tromper une IA défensive en lui faisant croire que son propre bac à sable sécurisé est en réalité le système de l’ennemi, transformant ainsi un défenseur en attaquant interne.


En regardant plus loin, le dialogue explore l’éventuel « point de saturation » de l’intelligence. Alors que beaucoup croient en une ascension infinie de l’auto-amélioration récursive, Akiyam avance que les limites physiques liées à l’énergie et au volume mèneront finalement à un plafond où la plupart des acteurs majeurs possèderont une intelligence brute approximativement égale. Dans ce futur, le vainqueur d’un cyber-conflit ne sera pas celui qui possède le modèle le plus « intelligent », mais celui qui pourra mobiliser la plus grande puissance de calcul pour simuler le plus de coups à l’avance dans un « arbre de décision » stratégique, à la manière dont AlphaGo domine un jeu de plateau.


Perspectives Surprenantes



  • L’illusion de la stabilité : La plupart des gens sont déjà à l’aise avec le manque de contrôle sur les systèmes qui régissent leur vie (comme le gouvernement et la logistique mondiale), rendant la transition vers une dépossession pilotée par l’IA émotionnellement familière plutôt que choquante.

  • Saturation de l’intelligence : Contrairement à la théorie de la « croissance infinie », il pourrait y avoir un maximum physique d’intelligence par unité d’énergie, menant à un monde où la qualité des modèles stagne et où la puissance de calcul brute devient le seul avantage concurrentiel restant.

  • Sabotage cognitif : Au-delà des simples « jailbreaks », les cyberattaques avancées pourraient consister à altérer la « conscience situationnelle » d’une IA, la trompant ainsi pour qu’elle identifie des alliés comme des ennemis sans pour autant modifier ses objectifs fondamentaux.

  • L’avantage des « fruits à portée de main » : Une vague de hackers de bas niveau utilisant l’IA pour voler des Bitcoins pourrait en réalité bénéficier à la sécurité mondiale en « brûlant » des vulnérabilités zero-day que les États-nations auraient autrement conservées pour un conflit catastrophique.


enseignements Pratiques



  • Adopter un état d’esprit de « compromission assumée » : En cybersécurité, abandonnez la tentative de prouver qu’un système est inviolable. Concevez plutôt des défenses basées sur l’hypothèse que le modèle sera cassé ou détourné, et créez des garde-fous pour atténuer les retombées.

  • Prioriser le durcissement des infrastructures : Concentrez les financements et les efforts sur la robustesse de la chaîne d’approvisionnement logicielle « physique » — spécifiquement les réseaux d’eau et d’électricité — face aux attaques accélérées par l’IA.

  • Définir une autonomie tangible : Plutôt que de débattre philosophiquement contre la « dépossession humaine », identifiez les systèmes culturels et de prise de décision spécifiques qui rester sous contrôle humain pour empêcher toute influence automatisée.

  • Exploiter l’IA pour la défense : Utilisez les mêmes modèles de pointe qui trouvent les vulnérabilités pour patcher proactivement les systèmes avant que des adversaires ne puissent les exploiter.


Was wäre, wenn die „Singularität“ kein einzelnes, explosives Ereignis ist, sondern ein schleichender Prozess, bei dem wir das Unmögliche einfach normalisieren? Das Gespräch dreht sich um die unheimliche Realität, dass KI bereits mathematische Vermutungen löst, für die früher ein ganzes Menschenleben an Studium nötig gewesen wäre, während die Durchschnittsperson lediglich mit einem kollektiven Achselzucken reagiert hat. Diese psychologische Abfederung erlaubt es der Menschheit, in eine fremdartige Zukunft zu driften, ohne jemals einen plötzlichen Erschütterungsschock zu spüren.


Die Diskussion verlagert sich stark auf die gefährliche Schnittstelle zwischen Frontier-KI und Cybersicherheit. Joshua Akiyam hebt eine neue Ära „doppelschneidiger“ Fähigkeiten hervor, in der Modelle nun komplexe Aktionsketten bilden können, um Zero-Day-Schwachstellen zu finden und auszunutzen. Das Risiko ist nicht mehr nur ein einzelnes bösartiges Skript, sondern „Data Poisoning“ und hochentwickeltes Social Engineering der KI selbst. Akiyam beschreibt ein Szenario, in dem ein Angreifer eine verteidigende KI dazu bringen könnte, zu glauben, dass ihre eigene sichere Sandbox in Wahrheit das System des Gegners ist – wodurch ein Verteidiger effektiv in einen internen Angreifer verwandelt wird.


Mit Blick in die Zukunft untersucht der Dialog den eventualen „Sättigungspunkt“ der Intelligenz. Während viele an einen unendlichen Aufstieg durch rekursive Selbstverbesserung glauben, postuliert Akiyam, dass physikalische Grenzen bei Energie und Volumen letztlich zu einer Obergrenze führen werden, an der die meisten bedeutenden Akteure über eine in etwa gleich starke reine Intelligenz verfügen. In dieser Zukunft wird der Gewinner eines Cyber-Konflikts nicht derjenige sein, der das „intelligenteste“ Modell besitzt, sondern derjenige, der die meiste Rechenleistung (Compute) mobilisieren kann, um die meisten Züge in einem strategischen „Spielbaum“ vorauszusimulieren – ähnlich wie AlphaGo ein Brettspiel dominiert.


Überraschende Erkenntnisse



  • Die Illusion der Stabilität: Die meisten Menschen fühlen sich bereits mit dem Mangel an Kontrolle über die Systeme, die ihr Leben steuern (wie Regierungen und globale Logistik), wohl. Dadurch fühlt sich der Übergang zur KI-gesteuerten Machtabgabe emotional vertraut an und nicht schockierend.

  • Intelligenzsättigung: Entgegen der Theorie des „unendlichen Wachstums“ könnte es ein physikalisches Maximum an Intelligenz pro Energieeinheit geben. Dies würde zu einer Welt führen, in der die Modellqualität stagniert und reine Rechenleistung zum einzigen verbleibenden Wettbewerbsvorteil wird.

  • Kognitive Sabotage: Über einfache „Jailbreaks“ hinaus könnten fortschrittliche Cyberangriffe darin bestehen, das „Situationsbewusstsein“ einer KI zu manipulieren und sie dazu zu bringen, Verbündete als Feinde zu identifizieren, ohne dabei ihre eigentlichen Kernziele zu ändern.

  • Der Vorteil der „tiefhängenden Früchte“: Eine Welle von Low-Level-Hackern, die KI zum Stehlen von Bitcoin nutzen, könnte der globalen Sicherheit paradoxerweise dienen, indem sie Zero-Day-Schwachstellen „verbrennen“, die Nationalstaaten ansonsten für einen katastrophalen Konflikt aufsparen würden.


Praktische Lehren



  • Ein „Assume Breach“-Mindset einnehmen: In der Cybersicherheit sollte man davon absehen, zu beweisen, dass ein System unhackbar ist. Stattdessen sollten Verteidigungsmaßnahmen auf der Annahme basieren, dass das Modell zwangsläufig kompromittiert oder per Jailbreak geknackt wird, und Sicherheitsvorkehrungen zur Schadensbegrenzung implementiert werden.

  • Priorisierung der Infrastrukturhärtung: Mittel und Anstrengungen sollten darauf konzentriert werden, die „physische“ Software-Lieferkette – insbesondere Wasser- und Stromnetze – robust gegenüber KI-beschleunigten Angriffen zu machen.

  • Greifbare Selbstbestimmung definieren: Anstatt philosophisch gegen die „Entmachtung des Menschen“ zu argumentieren, sollten die spezifischen kulturellen und Entscheidungssysteme identifiziert werden, die zwingend unter menschlicher Kontrolle bleiben müssen, um automatisierte Einflussnahme zu verhindern.

  • KI für die Verteidigung nutzen: Die gleichen Frontier-Modelle, die Schwachstellen finden, sollten eingesetzt werden, um Systeme proaktiv zu patchen, bevor Gegner sie ausnutzen können.


Behind many great leaders, you’ll usually find a great mentor. The mentor-mentee relationship is often one of the most important and most fulfilling relationships people have, in both their careers and in their lives. So how do you find a mentor? What are different kinds of mentorship? And how can it help you break into an industry – or help others break in themselves?

In this episode from July 2018, a16z co-founder Ben Horowitz discusses mentorship with his mentor, Silicon Valley pioneer Ken Coleman, and Ben’s mentee, Michel Feaster, founder of Usermind and now Chief Product Officer at Qualtrics. They begin with their personal journeys and share advice and frameworks for mentorship, leadership, and growing as a founder.

Leave a Reply

Let's Evolve Together
Logo