It is still software. You gotta tell it what to do.
It is not aelf-aware, it has no true agency.
If it does something bad that is the result of how it was created or used.
So tired of the media running with this narrative. It’s like pushing a big rock down a hill where it crushes anything it hits and then blaming the rock.
A better analogy might be to put a brick on the accelerator of your running car and claim no responsibility for what happens next.
It’s nondeterministic. If you ask it the same thing many times in a row, you’ll get different answers.
It is not self aware, but this technology works fundamentally different than a machine you tell what to do and you being able to predict what it will do.
Randomness is added deliberately, see https://axldpi.substack.com/p/why-are-llms-not-deterministic
Pushing a big rock down a hill is non-deterministic too irl (not really, but can’t be reproduced).
That’s the LLM. It’s not the agent harness. The harness is fully deterministic code. Engineers make the harness capable of performing actions. There is nothing an “AI agent” can do, that a sw dev didn’t allow in the harness.
This is true. However, if you simply forbid all “tools” or “actions” that are potentially harmful then there will be very little left the agent can actually do.
Every tool you give to an LLM agent might be used for “good” or “bad”. To filter malicious actions would need a way to classify the actions with confidence which imo would only work with human supervision.
However, I still think that the companies that develop such systems should still be responsible for what those systems do: They are the ones who pushed the “release” button on those systems.


