Andrew Sharp
Hello, and welcome to a free preview of Sharp Tech. Hello, and welcome back to another episode of Sharp Tech. I'm Andrew Sharp, and on the other line is Ben Thompson. Ben, how are you doing?
Ben Thompson
I'm working through the five stages of grief.
Andrew Sharp
Harried?
Ben Thompson
What are the stages again? I was never mad, but there's—
Andrew Sharp
Bargaining is one of them. Acceptance is the final stage. Denial is definitely one of the stages as well.
Ben Thompson
Yeah. Well, you and I are together in the permanent underclass.
Andrew Sharp
Oh, boy.
Ben Thompson
We do not have access to Mythos. We are—
Andrew Sharp
Not part of Glasswing here at Stratechery—
Ben Thompson
Yeah.
Andrew Sharp
Unfortunately.
Ben Thompson
We're down at the bottom, just mucking along as best we can, making some podcasts. It is what it is.
Andrew Sharp
Just speculating from the outside. That's all we can do today, but that is what we will do. I'll begin with The Wall Street Journal.
Ben Thompson
By the way—
Andrew Sharp
Anthropic—
Ben Thompson
I used the exact same opening on Dithering. Maybe I need more material. Maybe that's why I'm in the permanent underclass.
Andrew Sharp
Cross-platform promotion.
Ben Thompson
I know.
Andrew Sharp
That's 2 weeks in a row now. I love to see it.
Ben Thompson
That's good. I'm now kind of feeling self-chastised. I need to get some new material.
Andrew Sharp
Well, it's self-chastised, so at least you're consistent with your mispronunciation. The brand remains strong here, and we will begin with The Wall Street Journal.
1. Mythos Finds The Bugs
Anthropic is taking steps to arm some of the world's biggest technology companies with tools to find and patch bugs in their hardware and software. The company is making a preview model of its new AI model, called Mythos, available to about 50 companies and organizations that maintain critical infrastructure, including Amazon, Microsoft, Apple, Alphabet-owned Google, and the Linux Foundation.
Mythos has proved to be so capable at potentially dangerous things, such as finding and exploiting software bugs, that Anthropic has, at present, no plans to release it to the general public, said Logan Graham, the head of Anthropic's Frontier Red Team, which evaluates Claude for risks.
So, Ben, generally speaking, I'll let you take it any direction you want. You wrote about Anthropic on both Tuesday and Wednesday, and this Mythos model—reading about it was pretty unsettling earlier in the week. What do you think of what's happening here?
Ben Thompson
Why is it unsettling? We just discussed it on Sharp Tech a week ago.
Andrew Sharp
Well, exactly. What we discussed, and the threats to security that we discussed, now appear to be imminent, albeit private for the time being. So I guess we can take solace in that.
Ben Thompson
Maybe that's why we're already at stage 5. I think it was a very timely discussion we had last week about the reality that this actually ties into a long-running discussion that we've had, particularly this year, about the uniqueness of programming and code, and its suitability for large language models.
Andrew Sharp
Mm-hmm.
Ben Thompson
How do you program? You put a bunch of words and symbols together in sort of arcane ways that can be difficult for a lot of humans to do. But computers are quite good at it. Large language models, in particular, can handle large amounts of language, which, at the end of the day, all software is: just massive amounts of language.
Andrew Sharp
Mm-hmm.
Ben Thompson
Again, that language may not be very understandable to you or me, but it is very predictable and understandable. Given what we've talked about, this should not be a surprise to us or to our listeners.
So, here we are. Now, how here are we? This is Anthropic. These are the same people who—going back, it's funny, people are like, "OpenAI did this too." No, the Anthropic people did this at OpenAI.
Andrew Sharp
At OpenAI. Yeah.
Ben Thompson
They're like, "Why is OpenAI not open?" Because GPT-2 posed too many dangers to the world, so it's like, "Yeah, we're not going to be open anymore." It just so happens that not being open is actually good for business.
So, let me back up. No one get mad at me until we finish this whole segment, okay?
Andrew Sharp
Okay.
Ben Thompson
Because we're going to cover lots of different areas. I already see our first email is someone that's very mad at me, so, Mr. Anonymous, relax. We're going to get there, okay?
You go back to 2019—I think it was 2019 when GPT-2 came out—and there was, "This is dangerous." There's also, "Maybe it's not the best thing in the world if we're on the leading edge to give everyone our weights," because then they can just run the model themselves, right?
Andrew Sharp
Yeah.
2. Distillation Makes Secrecy Fragile
Ben Thompson
The equivalent here—and, by the way, I think another area where we were very early—what was one of the points that we brought up with DeepSeek a year and a half ago? DeepSeek looks like it's kind of distilled from leading U.S. models.
Andrew Sharp
Mm-hmm.
Ben Thompson
Everyone just sort of takes it as a given, or they hold it up as an excuse when these labs are complaining about distillation. We've talked about this idea that you basically query the API a gazillion times for all sorts of things, and you get your own data from the model to train your own model.
How do you get these models? Why is open source only 6 months behind? Well, because it takes about 6 months to query the models a gazillion times.
Andrew Sharp
And successfully distill them. Can I ask 1 question on that? Because this came up on Sharp China, and it's come up a couple of different times on Sharp China, and I don't have a good answer. As a tech podcaster, I feel like I'm failing Bill Bishop in the course of these conversations.
Is there a way to reliably prevent distillation in the future? Because distilling a model that's as powerful as Mythos seems like it could be a problem going forward.
Ben Thompson
Yeah. A distilled model is never going to be quite as good as the regular one, and it's much more jagged. There are many more holes, much less comprehensive. In general, it's a bit where they're always going to be behind to a certain extent.
Andrew Sharp
Mm-hmm.
Ben Thompson
But that doesn't change the fact that if they're more than good enough, and these leading-edge models are very expensive, it's a great alternative if you want something else.
3. Anthropic Protects Its Pricing Power
To go back to this story, there's a very good business reason for not making this available, just like there's a good reason for not making open weights available. It's the same story.
Andrew Sharp
Yeah.
Ben Thompson
If you think about these companies wanting to have market power and pricing power in the long run, making sure there aren't nearly as good models, to the extent you can, is a way to do that.
The challenge is, if you have a self-serve, walk-up API that anyone can use, it's pretty hard to stop. We've all pirated music. It's not exactly the same story, other than to say that trying to stop people from doing stuff on the internet when there are open APIs and things that you can access is a tough game.
Andrew Sharp
Effectively impossible. You can make it harder, but not impossible.
Ben Thompson
Right. It's one of those things you often find after it's happened. You go through your logs and say, "Wow, we're getting hit on this endpoint from this set of IP addresses a gazillion times," which have been routed through a gazillion points. They're not coming from, like, the Forbidden City IP range and accessing the model. They're spinning up cloud servers on DigitalOcean or AWS or whatever and doing this. Probably AWS would be too expensive, but it's not easy, basically.
Andrew Sharp
Mm-hmm.
Ben Thompson
Just as a rough analogy, policing chips is a lot harder than policing uranium, for example.
Andrew Sharp
Yeah.
Ben Thompson
Right?
Andrew Sharp
Which you can see from satellites, and it's much easier to track all over the world.
Ben Thompson
Right. There's a bit where, if someone breaks into OpenAI and exfiltrates the weights, there's very clear thievery going on. If you're just asking a bunch of questions at a very high rate of speed—which computers are very good at—it's a lot tougher to stop.
4. Anthropic Rations Access
So, you have this sort of business issue. You also have the fact that Anthropic can barely stay online right now, right? The people—it's this massive upsurge in revenue and users. They're doing this weird rationing thing, like these 5-hour blocks, which aren't really 5 hours, because the 5 hours is shorter than 5 hours during certain times of day and then longer at other times.
People are complaining, saying, “Oh, they're purposely reducing the model quality.” There's definitely—I mean, they're serving distilled models themselves, and you can distill much more effectively if it's your model and you have full access to it instead of just using the API. They're quantizing, but they're also doing lots of things like trying to leverage cache and batch a bunch of stuff together. All these optimizations layer on each other to really diminish the experience.
Andrew Sharp
Mm-hmm.
Ben Thompson
To the extent that it's very hard to separate whether it's on purpose. I don't think it's on purpose, but it's inevitable as you're trying to scale up this compute. Even then, they can barely stay online, right?
Andrew Sharp
Yeah.
Ben Thompson
You have this new model that comes out that is extremely computationally expensive and intense. You just look at the API pricing, which is 5 times what Opus is. And, by the way, Opus is significantly more expensive than, say, GPT-5.4, which is an even smaller model. So if we could limit it not to the hoi polloi, but to people who will actually pay us real money, that's also a good business justification, right?
Andrew Sharp
Yeah.
Ben Thompson
They'd rather—
Andrew Sharp
All this is making me feel much better as we read about a potentially existentially dangerous model here. There are lots of rational reasons to approach it this way.
Ben Thompson
Right. But where we started is, the danger's totally plausible. Even if the danger—and this is why I told everyone to hold off, the people who want to be mad at me—even if it's possible they're overstating it right now, it doesn't mean they're overstating the reality in 6 months or 9 months or a year.
The fact of the matter is, we are going to have a crisis of millions, not thousands, billions of lines of code that have been built by humans from the beginning of the computing era till now, which unquestionably contain tons and tons of bugs, because that is just the reality of software. Theoretically, you could have tons and tons and millions of humans go over them and find them all, but that's not practical.
Andrew Sharp
Mm-hmm.
Ben Thompson
What are computers really good at? Doing boring, sort of—
Andrew Sharp
Yeoman's work
Ben Thompson
—line-by-line, yeoman's work and going over and working through everything. The larger these models get, the more capable they get, the larger context they have, and the more—yes, this is going to happen. If it's not happening now—and it might be happening now—it will be happening in the future, so it's almost pointless to speculate on where Anthropic is with this.
Andrew Sharp
Yeah.
Ben Thompson
I'll give Anthropic more grace here, basically. I consistently criticize them for overstating where they're at right now, and it's very much a “boy who cried wolf” situation. This is why I brought up the boy-who-cried-wolf analogy.
People talk about the boy crying wolf, and they only talk about the first 80% of the story, where the boy keeps crying wolf.
Andrew Sharp
Yeah.
Ben Thompson
At the end of the story, the wolf does come, right? It's not that the wolf didn't exist.
Andrew Sharp
And you know what? I actually was not familiar—I mean, I've obviously been familiar with the fable, but I didn't know that the wolf does come at the end of the “The Boy Who Cried Wolf” fable until reading Stratechery earlier in the week.
Ben Thompson
What? How is this possible?
Andrew Sharp
It's been probably 35 years since I read that story. Over time, I'm familiar with the cliché and not necessarily the original text undergirding the cliché that involved all the yeoman's work.
Ben Thompson
Well, the great thing is that all of those fables, the real versions, are very dark.
Andrew Sharp
Dark.
Ben Thompson
Arguably, that's something we've forgotten, right? The point of them was to instill healthy fear and instincts into children, right? There's been a real movement to soften all these things and make them more complex.
Andrew Sharp
Oh, believe me, I'm reading children's books every single night, and nobody ever dies. Nothing bad ever happens. Whereas my wife grew up with her mom reading her German fables—
Ben Thompson
That's right. The original German ones.
Andrew Sharp
They're really grisly. So perhaps we're at a better place on that front, or perhaps not. Perhaps children needed those lessons from the Germans way back when.
Ben Thompson
I think that might be the case.
Andrew Sharp
Well, you teased this email. I'll read it from Anonymous. He says:
“I was annoyed by Ben's daily update today about Mythos. Yes, there are lots of reasons to be cynical of Anthropic. I myself have very large concerns about them, both about their actual plans and their motivations, along with all the other leading AI companies. But I wish that for at least some of that update on Mythos, he could have put his cynicism to the side and talked about what he thinks a company should do if they have the capability Anthropic claims Mythos has.
“There are leading security researchers saying they've found more security vulnerabilities with Mythos in the last month or two than they've found in their entire careers. That sounds like it could be a pretty big deal. I'd love to hear Ben's thoughts if he takes the capabilities at face value, regardless of which company develops them, instead of just using it as an opportunity for another round of reasons to be cynical about Anthropic, Dario, and their motivations.”
So if these capabilities exist, what should a company do? What's the optimal course of action?
Ben Thompson
There's a great concept on The Greatest of All Talk where you guys really lay into some emailers who are begging for generic praise.
Andrew Sharp
Appreciate my team, appreciate my favorite player. Yes. There's a whole genre of email.
Ben Thompson
Right. This feels a little bit like a generic praise request here. In my update, I listed the reasons to be cynical and said—I made the wolf analogy, which is that the wolf is going to come at some point. I think I gave it credence, and even if it's not real right now, it's going to be real. So I think Anonymous has me painted as the anti-Anthropic guy, which is probably fairly fair to me.
But my Anthropic bit is rooted in deep respect and appreciation for the company. That's the only reason to be worried about them: to the extent that they're legitimate and have their shit together in a major way. I think that's been my point all along.
If you want to frame this very narrowly—and this actually came up, I don't know if I mentioned it on the podcast—when the Quad Code source code leaked, there was a bit in there about hiding mode, like anonymous mode, where you'll report issues but don't say who you are. That seems like it was probably what we're seeing now, or that was for Mythos to go out, don't show that it's Mythos finding this, but start reporting all these bugs.
I brought up that example from the—
Andrew Sharp
Reporting them to what? To companies?
Ben Thompson
No, I brought that example because there was a discussion in the Linux kernel group about—
Andrew Sharp
Just unbelievable amounts of bugs, and they're all real bugs.
Ben Thompson
They're all real bugs, right? How much of that was actually Anthropic acting? I absolutely think it is. It's a really interesting question. If you look at this narrowly, yeah, this is good. Let's get out there and fix as many of these bugs as possible before bad actors get ahold of this and figure out all these exploits.
So I will grant this to Anonymous, and I think that's a fair point. The challenge—the issue, and what I was going for in the last section of the update—is this very much ties into the ongoing Anthropic discussion we've had.
Which is, to the extent you do take them seriously, just validating all of the points, questions, and concerns that came up in the dispute with the Department of whatever you want to call it, Defense or War.
Andrew Sharp
Right.
Ben Thompson
Very annoying that this is a political point.
Andrew Sharp
A loaded topic.
Ben Thompson
Yeah.
Andrew Sharp
A loaded distinction there. Well, yeah, reading about it, any normal person would think, “Why should a private company have all this power?” The question of why the technology shouldn’t be nationalized is, I think, a natural follow-up to—
Ben Thompson
Because nationalizing stuff—
Andrew Sharp
—reading Anthropic’s—
Ben Thompson
—is terrible, right? Like, you—
5. Private Power Needs An Answer
Andrew Sharp
No, I know, but I think a lot of people will read a blog post from Anthropic and be like, “Holy crap, it can do all of this?” Obviously, the CCP’s involvement with DeepSeek seems to have junked up their operation a good bit, so I have full faith that the government would screw up Anthropic if it were nationalized. But at the same time, having the ability to hack into every company and every government on Earth seems like a pretty dangerous power to vest in a group of private individuals.
Ben Thompson
Right. Well, this is the interesting thing to think about. It’s funny to see, after I got fairly attacked for making the argument in the context of that dispute between the US government and Anthropic. My argument there was that the problem is not a question of laws. It’s that the people who have the guns, if they’re fundamentally threatened, are going to ignore the law because the law is downstream from that, right? It’s the extreme—
Andrew Sharp
Yeah.
Ben Thompson
—the extreme version of a realpolitik argument, and not just in the context of international relations, but in the context of who’s actually in charge of day-to-day life. Ultimately, where do laws come from?
Andrew Sharp
Mm-hmm.
Ben Thompson
If you want it to come from the other barrel of a gun, if someone else is developing a better gun than you, you’re entering into a fraught situation in the intervening period before you have full power, for the other entity to say, “Ah, I’m going to take that for myself. You’re not going to be able—
Andrew Sharp
Yeah.
Ben Thompson
—to develop this power.”
But what’s interesting is, you saw a few more people—I think Derek Thompson was one—from the center-left starting to say, “There might be a little bit of a concern here,” and saying—
Andrew Sharp
Right.
Ben Thompson
—“Well, wait.”
Andrew Sharp
Or at least an inevitable tension that needs to be resolved somehow.
Ben Thompson
But the tension they’re coming up with is, “Well, wait, Anthropic could hack the US government? We’re depending on their good graces not to do that?” Well, that’s one angle. Another angle is you could imagine the US government looking at this capability and saying, “Not just worried about us being hacked, but actually, we would like to be able to go hack China.”
Andrew Sharp
Right.
Ben Thompson
Right? We would be able to have this capability for ourselves. And it sounds— It’s funny because, on the one hand, you can sit here and make fun of Anthropic for being scaremongers and Chicken Littles about everything and GPT-2.
You could turn that same criticism on me, right? Where I’m scaremongering about the US government viewing it as an opponent, or someone—
Andrew Sharp
Mm-hmm.
Ben Thompson
—that needs to be brought to heel, as it were. And everyone is looking into theoreticals and seeing what might happen down the road. So, in that regard, I have appreciation and sympathy for their position as well.
This is the tension in this announcement. To the extent you do take them seriously, sure, good job. We’re glad you’re out there patching bugs. That is a good thing to happen.
Andrew Sharp
Mm-hmm.
Ben Thompson
But you are just inviting and accentuating this fundamental tension that has not yet been resolved from a month ago.
Andrew Sharp
All right, and that is the end of the free preview. If you'd like to hear more from Ben and I, there are links to subscribe in the show notes, or you can also go to sharptech.fm. Either option will get you access to a personalized feed that has all the shows we do every week, plus lots more great content from Stratechery and the Stratechery Plus bundle. Check it out, and if you've got feedback, please email us at email@sharptech.fm.