[BidClub_]
The a16z Show · · 42 分钟

机器人、深度伪造与 AI 智能体正迫使互联网建立新的身份层|a16z 对话 Alex Blania

Ben HorowitzErik TorenbergAlex Blania

YouTube
TL;DR
  • Alex Blania 认为,AI 智能体将迫使平台区分真人、代表真人行事的智能体,以及自主智能体。 获得明确授权后,代理智能体可以在其所有者的 X 或 Instagram 账户上发帖,但核心属性始终是唯一性:理想情况下,一人控制一个账户,至多是有限数量的账户,并通过保护隐私的方式完成验证。纯数字声誉体系注定失效,因为 AI 可以长期维护 GitHub 账户,还能彼此证明对方是人类。

  • World ID 的押注是,全球唯一性需要高熵虹膜生物识别,而不是传统的人脸或指纹核验。 Face ID 等手机系统解决的是 1 对 1 身份认证;真人证明则要求对全网参与者进行 1 对 N 比较,而人脸和指纹在用户达到数千万后最终会触及准确率上限。Orb 会核验虹膜唯一性,并通过多种传感器抵御屏幕展示和重放攻击。

  • 其隐私架构将生物特征核验与个人身份分离,而不是建立一个集中式虹膜数据库。 Orb 计算虹膜编码,再通过多方安全计算将其拆分给多台计算机,最终只返回“是的,该个体具有唯一性”;留在手机中的秘密信息和零知识证明,随后让用户向平台证明自己是唯一用户,而 World ID 和平台都无法获知其真实身份。

  • Blania 预计,随着智能成本下降、智能体能力增强,今天的 bot 问题在1到2年内看起来会微不足道。 他表示:“我们现在看到的还不到未来形态的1%”,而威胁不仅是数量级的扩张,也包括极具说服力的操纵:在一项 Change My Mind 实验中,AI 参与者根据用户经历和政治动机定制论点。Ben Horowitz 补充说,“AI 非常擅长编程人类”——远胜于人类编程 AI——Blania 对此表示认同。

  • 短期需求覆盖约会、视频通话、游戏、创作者平台和数字广告。 Tinder 在日本的测试为通过 Orb 验证的用户加上真人徽章,下一步可能还会核验个人资料照片是否与经过验证的本人一致。Erik Torenberg 预计,实时、照片级逼真的深度伪造将在大约1年内成为商品化能力。广告主还要面对 Alex 提出的递归式假设:“我制作了100个 AI 视频,然后让100万个人工智能去观看。”

  • 公司称,市场风险已经转变为一个资本密集型的执行问题,并伴随强大的网络效应。 公司披露,App 内已有1,800万名完成验证的用户、总用户数4,000万,但估计要让全美用户在15分钟内触达一台 Orb,需要约5万台设备。未来1年,公司约90%的精力预计将投入美国市场;Walmart 或 Starbucks 规模的铺设、独立场所,以及“Orb on Demand”摩托车服务都在部署计划之中。

  • 对投资者而言,乐观情景是:随着智能成本近乎指数级下降,一个稀缺的真人网络将变得更有价值,但分发和用户习惯养成仍是关键瓶颈。 Blania 表示,平台兴趣的提升已经让这件事“更像一个执行问题,而不再是市场风险”。他的核心判断是,在 AI 世界里,真人网络将极其重要,并受益于强大的网络效应。能力较弱的手机端 Face Check 可能将一人限制在10个或20个账户,而不是100个,但 Blania 认为这只是过渡方案,因为深度伪造将“从根本上击穿”它。

  • Blania 还将真人证明定义为公共基础设施。 他认为,政府需要以密码学为基础的强力手段,识别唯一真人及其所属国家的公民身份、更高效地发放资金并保护民主。他声称,COVID 刺激计划中有4,000亿美元被盗,即便验证的只是唯一真人而非本国公民,也有助于资金发放;他还表示,AI 规模化冒充、为另一个时代设计的邮寄选票,以及 Social Security 和 Medicare 中的欺诈,否则都可能侵蚀民意。

摘要 · 为研究而整理的核心内容

1. 真人证明本质上是唯一性问题

  • Blania 将未来互联网参与者分为三类:真人、获得真人授权后代其行事的智能体,以及自主智能体。获得明确权限后,授权智能体可以在其所有者的 X 或 Instagram 账户上发帖,但账户仍然对应一个唯一真人。

  • 系统需要验证的并不只是注册时是否有真人存在。它必须确保“每一个在平台上进行互动的个体都只有一个账户,理想情况下就是一个账户”,或至多拥有有限数量的账户,并持续验证控制权始终掌握在同一个人手中。

  • 今天的 bot 过滤本质上是一场注定落后的追赶战。Blania 说,一个真人可能向外派出1万或10万个 AI,而 X 和 Twitter 可能每天都在试图拦截数百万个这样的账户。他的前提是,一旦 AI 能够复制 AI 所能完成的一切数字行为,单靠数字行为和历史记录就无法可靠证明对方是人类。

  • 因此,信任网络从根基上就不成立。AI 可以养大一个 GitHub 账户、持续发帖、拥有其他账户,还能“向另外5个 AI 证明这些确实是人类”,从而构造出一张看似可信、实则完全合成的声誉网络。

2. 虹膜验证解决的是手机无法解决的 1 对 N 问题

  • Blania 排除了以政府身份作为全球通用基础,因为这会威胁匿名性、让言论基础设施集中在国家手中,也无法解决全球性问题。他指出,Singapore 的基础设施或许可以做到完美,但它无法覆盖一个拥有30亿用户、横跨多个司法辖区的 Meta 级服务。

  • Face ID 回答的是当前人脸是否匹配一个已存储的特征向量,即“1 对 1 身份认证”。真人证明则必须确认新申请者从未在所有现有参与者中注册过,随着网络扩大,这一任务变成 1 对 N 匹配,所需信息量呈指数级增长。

  • Blania 认为,人脸和指纹在用户达到数千万后最终会触及准确率上限,而虹膜足够独特,可以应对这一问题。他还预计,随着 AR 和 VR 硬件普及,虹膜扫描会逐渐成为常态,并以 Apple Vision Pro 中的虹膜 ID 为例。

  • 验证和认证仍是两件不同的事。Orb 使用覆盖电磁频谱的多种传感器,排除屏幕展示等重放攻击;未来的认证可能在足够可信的新款手机上完成,但较老的 Android 设备可能允许深度伪造内容被展示在屏幕上,或直接注入摄像头视频流。有些用户每年可能仍需回到 Orb 重新验证几次。

3. 隐私取决于生物特征在离开 Orb 前就被拆分

  • 主持人直截了当地提出最初的恐惧:“天啊,他们拿到了我的眼球。”Blania 的回应是,唯一性不可能完全留在设备本地——“总得有东西离开设备”——但 World ID 或任何单一数据库都不需要持有完整的生物特征表示。

  • Orb 在本地采集图像并计算虹膜编码,再将编码拆成多个部分,分别发送给不同的计算机。多方安全计算让各方能够共同判断唯一性,同时“没有任何一方拥有完整信息”,计算过程中也是如此。

  • 返回的只有结论:“是的,该个体具有唯一性。”另有一份秘密信息留在用户手机中;此后,用户可以通过零知识证明向社交网络证明,这份秘密属于一名唯一注册者,同时不会向社交网络或 World ID 暴露自己的身份。

4. 合成人物同时威胁信任和互联网经济

  • Tinder 在日本的测试市场是最清晰的现实案例:通过 Orb 验证的用户会获得一个徽章,表明该资料由真人控制。下一步可能是将 World ID 与个人资料照片关联起来,既证明参与者是真人,也证明“就是你所声称的那个人”。

  • Erik 预计,当照片级、实时深度伪造能够在涉及借款的通话中冒充基金经理或其他高价值目标时,视频会议将进入高风险阶段。Blania 表示,这类能力已经非常接近现实。

  • 游戏提出的是另一种真实性需求:玩家投入数小时训练,甚至押上金钱,最后却发现自己“被一个在所有维度都超越人类的 AI 击溃”。问题不在于 AI 操作游戏是否有趣,而在于参与者是否知道自己究竟在和什么竞争。

  • 内容平台面临市场两端的欺诈。Alex 说,他听说有一位创作者每天制作的 AI 生成视频“他认为大约有100个”,每月收入达数万美元。主持人还分别提到,有些刷量农场让数千部手机全天候观看视频;Ben 认为这对广告主提供的价值为零。Alex 则开玩笑说,可以让100万个人工智能去观看这些视频。对于那些支持建立在与真实创作者存在关系感之上的粉丝而言,内容是否源自真人同样重要。

5. 规模化说服让来源证明不再只是反垃圾信息功能

  • Blania 说,考虑到智能成本几乎呈指数级下降、智能体能力却呈超线性增长,当前状况“还不到大概1到2年后形态的1%”。未来的智能体不只是淹没信息渠道,还可能理解每一个人,再以对其最有效的方式分别沟通。

  • 他给出的最有力案例,是 University of Zurich 围绕 Change My Mind subreddit 进行的一项实验。据称,AI 系统会查看用户资料,推断其政治动机和沟通风格,再以超越人类的效果定制回应:“AI 非常擅长‘编程人类’(AIs are really good at programming humans)。”

  • Ben 指出,电影等虚构内容不需要对现实作出承诺;而 TikTok 式媒体的价值,则来自它与现实或某个具体人物的关联。即便 Gemini 根据科学论文生成的播客既有娱乐性,也有现实依据,受众和广告主仍然会从了解其制作方式中获益,也会关心究竟是人类还是 AI 看了这段内容。

  • Blania 预计,当真实用户开始频繁被指责为 bot 时,人们会“更加以自己是人类为荣”。主持人认为,无法划分真人与 AI 的平台会越来越失去自洽,而 Blania 预计,仅靠手机的人脸生物识别会先被尝试,随后被深度伪造击穿。

6. 这套论点已经从市场风险演变为分发竞赛

  • 大约6年前最初的融资说法其实就没有变:网络空间需要真人证明,而由此形成的真人网络可以发展出强大的网络效应。Ben Horowitz 回忆,在 ChatGPT 出现之前,Orb“简直太离谱了”——要扫描人的视网膜;当时真正的问题是时间点,而不是合成身份最终是否会成为问题。

  • ChatGPT 之后,人们开始参与讨论,但仍把问题视为多年以后的事。Blania 认为,最近出现的“Cloud Bots and Mobile Book”时刻,才让更多人开始主动联系团队。他现在认为,这“更像一个执行问题,而不再是市场风险”,但经济模式、平台接入、用户行为和设备分发仍然困难重重。

  • Blania 将推广定义为一个三方协调问题:平台必须使用这项技术,用户必须能够触达设备,而三者合并后的效用必须足以让大量用户愿意使用。3个条件需要大致同时兑现。

  • 目前披露的覆盖规模是1,800万名完成验证的用户,以及 App 内4,000万名总用户。要让全美用户在15分钟内触达一台 Orb,可能需要约5万台设备;由于上一届政府时期的加密货币政策,公司此前对美国投入有限,未来1年约90%的精力预计将转向美国市场。Blania 表示,他希望 Clarity Act 很快获得通过。

  • 分发网络可能由 Walmart 或 Starbucks 等大型合作伙伴、独立咖啡店,以及 DMV 等政府场所共同构成。Blania 说,团队很快将推出“Orb on Demand”,由摩托车把 Orb 送到 Bay Area 或 New York 的用户手中,用时约50分钟。他表示,目前还没有看到真正的竞争者,但既然这个问题已经变得显而易见,竞争者预计会出现。

  • Face Check 提供了一个过渡性的匿名层,可能将一人可持有的账户数限制在10个或20个,而不是100个,但 Blania 强调,这只是临时方案,因为深度伪造会让它失效。其运营原则是:“凡是可能对解决这个问题有用的东西,我们就直接把它做出来。”

7. Blania 也将真人证明视为公共基础设施

  • Blania 认为,政府需要以密码学为基础的强力基础设施,识别谁是哪国公民,并更高效地向本国公民发放资金。他声称,COVID 刺激计划中有4,000亿美元被盗,并认为,即便验证的只是唯一真人而非本国公民,也有助于资金发放。

  • 他称 SAVE Act 很粗糙,但“也不能说完全疯了”,因为在他看来,社会实际上并不知道投票者究竟是真人,或者是否仍然在世。他认为,邮寄选票是为另一个时代设计的;大规模 AI 冒充叠加失灵的 Social Security 体系,可能让民意本身消失。

  • 他将同样的逻辑延伸至 Social Security、Medicare 和其他社会项目,认为这些体系效率低下且欺诈严重。在他看来,真人证明只是更大规模基础设施升级的一部分,目标是更高效地转移福利并维护民主。

Alex Blania

How do you prove somebody’s human? It is a surprisingly hard problem. I think people are going to start getting accused of being bots. What we currently see is less than 1% of what it will look like in probably a year or two.

Alex Blania

The idea that AGI will lead to some very fundamental shift seems obvious.

Alex Blania

AIs are really good at programming humans—much better than humans are at programming AIs.

Alex Blania

Absolutely.

Alex Blania

AI will be able to have a GitHub account, post, and attest to 5 other AIs that these are, in fact, humans, even though they’re not.

Alex Blania

I say, if you don’t take it seriously now—

Alex Blania

Alex, welcome to the podcast. Great to have you.

Alex Blania

Thanks for having me.

Alex Blania

Proof of human is having a moment right now. Why don’t you first give some background for people who are unfamiliar? What is the moment that’s happening, and how did we get here?

Alex Blania

What is proof of human? Proof of human, as the name suggests, is: Do you know whether you’re interacting with a human or something else on the internet? I actually think that the kinds of questions we’re now asking are: Are you interacting with a human, an agent on behalf of a human, or just an agent? I think these are roughly the 3 areas that we want to split apart.

Alex Blania

Describe a little bit the difference between just an agent and an agent acting on behalf of a human. How do you see that distinction?

Alex Blania

I’ll quickly explain the term “proof of human” and what’s hard about it, and then I’ll explain how that fits into an agent on behalf of a human. What proof of humanity really means is that every individual who interacts on a platform has only one—ideally one—account, or a limited number of accounts, and remains the owner of that account. That’s the property you’re looking for.

You’re looking for an initial verification that ideally should be anonymous or extremely privacy-preserving, and then ongoing authentication that the same person remains in control of their account. There are some secondary properties that are good to have, but that tells you that the really hard thing is uniqueness.

What’s happening on a platform like Twitter right now is that there are all these accounts—all these bots in the replies. There’s probably 1 human sitting somewhere and sending out 10,000 or 100,000 AIs. There’s this catch-up game where Twitter and X are trying to find them and block probably millions a day of these.

Alex Blania

Which is, like, 1/100th of the bots?

Alex Blania

That’s right. That’s how it feels. And then, with an agent on behalf of a human, I think all of us will have agents. It’s unclear what that will look like. Is it going to be 1, or are there multiple ones, maybe with different tasks and even different types of characters?

I think it will then come down to: I approve a certain action of my agent. I give it certain rights. So, act on my behalf. Post to my X account. Post to my Instagram, for example.

Alex Blania

But it’s my Instagram, and I’m a unique human that owns that.

Alex Blania

That’s right. X or Instagram could decide whether that’s actually something they want as a platform.

Alex Blania

Right. That’s how you could do it. That makes sense. So, how do you prove somebody’s human? It is a surprisingly hard problem.

Alex Blania

Those agents are very clever. We started this company a couple of years ago, way before ChatGPT and before all of that. We took it as an assumption that eventually we would have AIs that both pass the Turing test—they can claim to be human, and you will not be able to tell them apart on the internet—and are highly agentic and just run around and do their own thing.

That makes it really hard, because back when we started the company, there were roughly 3 big ideas that people were interested in. One was the idea of a web of trust, or a related idea: You look at how someone behaves on the internet or has behaved in the past.

Usually, it was a combination of having a certain number of accounts that you’ve owned for a couple of years and then posting or commenting regularly on GitHub. Those were the kinds of things people were using. Let’s say all 3 of us have those accounts, and then I attest that I know you in the real world. That’s how you would build a certain graph.

That was a very hot idea back then, but we disregarded it basically immediately because we assumed that eventually everything that’s digital and that an AI can do, an AI will be able to do as well.

Alex Blania

We’re there.

Alex Blania

Exactly. An AI will be able to have a GitHub account, post, own an account, and attest to 5 other AIs that these are, in fact, humans, even though they’re not.

Area number 2 was to just use government IDs for everything, which we also immediately disregarded for a couple of reasons. I think it’s strictly better if the government would not control such an infrastructure in terms of free speech and actually breaking that apart.

Alex Blania

Right. You lose anonymity instantly, right?

Alex Blania

You could hypothetically set up a system that maybe preserves it, but it’s very hard to do. The other thing is that the government ID identity system is just not built for that.

What’s so hard about this problem is that it’s going to be a global problem. It doesn’t really matter if 1 government has the perfect infrastructure. For example, Singapore is an example of a government that has perfect infrastructure all around.

But that barely matters, because Meta is a global product with 3 billion users, and there are a lot of other countries.

Alex Blania

Singapore is what, like, 2 million people or a million people?

Alex Blania

Yeah. So, do you want to lock everyone else out? There’s a long list of other reasons why we disregarded that basically immediately.

The last one is biometrics, which immediately gives us this ick reaction. It even went further, because what’s so hard about this problem, as I mentioned in the beginning, is uniqueness.

In very simple words, you can describe the problem like this: What does Face ID do? Face ID checks that I’m the same person again when using my phone. It’s a one-to-one authentication. There’s an embedding stored on my phone; it takes a picture of my face, creates a new picture, compares it to the previous one, and if it’s close enough, I can use my phone.

That’s one-to-one: 1 embedding to 1 new embedding. To solve the proof-of-human problem, you need to distinguish 1 new individual from all previous individuals. You need to make sure that Ben is trying to sign up and that Ben did not sign up before.

Suddenly, it goes from one-to-one to one-to-N, and N is the size of your network, essentially, that you’re trying to prove it to. You can do the math and calculate how much mathematical entropy—how much information, just information-theoretically—you need to prove that.

It turns out to be a pretty high number because it’s an exponential problem. You can do the math and find out that things like faces or even fingerprints don’t work. You would basically hit a wall after tens of millions of users.

Alex Blania

Right. And so then you end up with something like the iris, which is the muscle of your eye, that actually has enough entropy.

Alex Blania

That’s unique enough. You also have to solve the problem that biometrics have historically been subject to replay attacks. I may not have your eyeball, but I’ve got enough information that I can run a replay attack on you.

It’s important to split up the problem into verification, which is essentially, in old terms, like getting your passport, and authentication, which is you showing your passport constantly for certain kinds of things.

On the verification piece, if you know Worldcoin, you know that we’ve built this thing called an Orb. It’s doing a lot of things to prevent these kinds of attacks. For example, it has multiple sensors in the electromagnetic spectrum to make sure that you can’t show it a display and have it recognize that.

On that side, we’ve got it handled. On the consumer side, where it should then reauthenticate, it turns out to be much harder, because you would need to trust the phone in some sense.

Mhm. Because what we actually do in that moment is, when you verify with an Orb, we not only check your uniqueness in a fully anonymous and privacy-preserving way—and we should talk about that—but we also send to your phone a signed face image that you can later use to reauthenticate against it. With a new iPhone, you can have a meaningful amount of trust against that, but with old Android phones, basically not.

Alex Blania

Oh, yeah, yeah, yeah.

Alex Blania

Because you can just show a deepfake, essentially, either through a display or directly inject it into the camera stream. So that’s the problem. It’s going to be a mix of: if you have a new enough iPhone or a newer phone in general, then you can just reauthenticate against the picture that you took on verification. Otherwise, you would probably have to go back to an Orb somewhat frequently, let’s say a couple of times a year.

Alex Blania

I see. Right, to reauthenticate.

Alex Blania

Yeah, that’s right.

Alex Blania

Interesting. And then one of the incorrect criticisms of the approach early was, “Oh my God, they’ve got my eyeball.” Now they somehow have access to my privacy, and they’re going to do all these things to me. They have my iris, and then Worldcoin can impersonate me, and all these kinds of things. But that’s not the case, and that was also a nontrivial engineering problem.

Alex Blania

It was very much nontrivial. Actually, I think one point about the iris that people don’t appreciate enough is that it was a bet we took back then: iris will turn out to be super normal as a modality, just because I think we will all wear AR and VR systems that do that. Apple already does it.

Erik Torenberg

Yep.

Alex Blania

Apple already has iris ID in the Vision Pro. So I think it’s going to become something that we use across many different devices and normalize in that sense.

Erik Torenberg

So maybe that’s a general point.

Alex Blania

But on the privacy piece, that took us a lot of time because, when we decided back then—with our assumptions, which was 6 years ago—that we would need a custom hardware device for biometrics, it was actually quite scary to come to that conclusion.

Erik Torenberg

That’s an expensive conclusion.

Alex Blania

It’s very expensive. Then there was the idea that you would need to distribute them all over the world. That just assumes that you would be able to somehow bring up billions of dollars and undertake a massive effort to roll this out across the world. But then there was also the privacy challenge: how could you build such a system with all the requirements that we care about? The 2 main high-level ideas for how to solve it were multi-party computation and zero-knowledge proofs.

Erik Torenberg

Mhm.

Alex Blania

Again, what is different from Face ID? Face ID can be very private because the embedding is stored on the phone. It doesn’t have to leave the phone ever, because it’s just you against you in the past. But to check uniqueness, you need to check against all previous people, so something needs to leave.

Erik Torenberg

Yeah, something needs to leave and be compared to someone else.

Alex Blania

And that’s a much harder challenge. How we approach that is with multi-party computation. In our case, when you verify with an Orb, we take all these pictures. They get computed on the device, and then they actually get split up into multiple pieces. For example, we take a picture of your iris, calculate an iris code, then break that iris code into multiple pieces and send it to multiple computers, such that there is no central database. No one actually has the information about you.

Erik Torenberg

Right.

Alex Blania

Then you do some clever tricks for how these different parties need to come together to do a computation that still leaves the pieces apart.

Erik Torenberg

Right, right, right.

Alex Blania

Yeah, so no one has the whole thing, and also during the computation no one has the whole thing. They do some clever interactions to come to the conclusion—

Erik Torenberg

Like a zero-knowledge-proof kind of technique.

Alex Blania

It’s very different, but in terms of the properties it achieves, it’s somewhat similar: no one knows anything about you, but you can together make a statement about you. You send it to this multi-party computation, and what comes back is, “Yes, that individual is unique.”

And the second thing we do is separate all of this from you with a zero-knowledge proof. Meaning, you have the secret on your phone, but no one else has it. No server has it; we don’t have it. Then you can later go back to this multi-party computation and say, “Hey, I have a secret that is part of that computation, and I am in fact unique.” Then you can prove that to a platform. You could go to a social network and prove that you’re a unique user to the social platform without us knowing anything about you or the social network knowing anything about you.

It’s just very counterintuitive that even though it uses biometrics, you preserve anonymity and extreme levels of privacy, which I think is super cool.

Erik Torenberg

Social media is one kind of vector of things that were annoying and are now becoming overwhelming in terms of just bots, particularly with psyops, propaganda, and all these kinds of things. What are some of the other uses of bots that are going to be impossible to live with if we don’t get to proof of human in the future?

Alex Blania

Actually, I think the simple model I have for it is that every moment on the internet that is primarily about humans interacting with each other—or even indirectly interacting with each other—is affected. You can start with simple ones like dating. It really matters whether the other side is in fact a person.

Erik Torenberg

Yep. What if the other side is in fact a person?

Alex Blania

And the person you expected them to be.

Erik Torenberg

Well, I’ve got bad news for listeners.

Alex Blania

We had this problem even before the whole catfishing thing.

Erik Torenberg

Yeah, exactly.

Alex Blania

That’s an obvious one. Tinder is already using it for that reason.

Erik Torenberg

What’s the Tinder use case?

Alex Blania

We started in Japan as a test market, and it’s essentially exactly what we just discussed. If you’ve verified with an Orb, you get a little badge that signals to other people that you are in fact a human. So it has a high level of verification.

What will come next is that you’re actually the person you claim to be. Meaning, you have a World ID that is associated with the profile pictures that you use, so you just run a quick check that this is all correct. You then know you’re not interacting with a bot, but also that you’re interacting with a fully authentic profile.

Erik Torenberg

Yeah. Another fun one, because I think it’s somewhat counterintuitive, but I think it will be video conferencing.

Alex Blania

Mhm. Because you already have deepfakes.

Erik Torenberg

Yeah, I just don’t feel like going to this video conference with my deepfake on.

Alex Blania

Actually, you raised it to me first, and that’s why we started building a product for it. It will actually start with very high-value users—for example, people like yourself who maybe manage a fund, where sometimes calls could be very high-value if they’re about borrowing money or—

Erik Torenberg

Oh, yeah, yeah. Somebody can— It’s still slightly hypothetical because these things are not fully real time, and you can somehow—

Alex Blania

They’re very close.

Erik Torenberg

But they’re very close. And so I think, in a year from now, it’s just going to be a full commodity. It’s going to be super photorealistic and absolutely real time, and you will just not know anything anymore on these video calls. So I think that’s another one.

Alex Blania

I think another one will be gaming. It’s fun, but it’s going to be gaming.

Erik Torenberg

Yeah, because gamers really care—

Alex Blania

Oh, yeah, yeah. Because gamers really care that they’re not playing an AI.

Erik Torenberg

Holy cow, that’s frustrating. Especially if we bet money.

Alex Blania

Yeah, exactly. You lose money, you train multiple hours a day to get really good at this thing, and then suddenly you get destroyed by an AI that is superhuman in every dimension.

Funny enough, I wonder what you think about this, because I don’t have a good mental model for it. Even the whole model for video platforms, I think, is about to break. There are a couple of dimensions to the problem, but one is that if the creation of content is becoming super scalable. For example, I heard about this one guy who created, I think, on the order of 100 videos a day on YouTube and made tens of thousands of dollars a month. All of them were fully AI-generated.

Erik Torenberg

Yeah.

Alex Blania

People just fell for it. So now the question is: is that actually something that YouTube wants to monetize that way?

Erik Torenberg

Yeah, well, it’s interesting, right? They fell for it.

Alex Blania

But maybe they liked it. They’re like, “That could be.” But it would sure be nice to know, “Okay, this is a human video, or this is an AI video.” Actually, my thesis about this is something along the lines of: I think there are categories of content that are clearly just fictional. Movies are that, you know? You don’t care that there’s any connection to reality. It’s just a fully fictional story. But if you think about something like TikTok, or all these kinds of things, people actually really care about them mostly because there is some connection to reality.

Ben Horowitz

Yeah. Well, there’s reality and there’s a connection to a human, right? You can create a pretty good podcast—you can take a scientific paper and give it to Gemini and say, “Make this into a podcast,” and it’ll be a pretty entertaining podcast. It will be reality in that it came from some real thing, but you would like to know that.

Erik Torenberg

You would like to know that. Yeah, I would like to know that. As an advertiser, you’d like to know: did a human watch it?

Erik Torenberg

Or did an AI watch it? [laughter]

Alex Blania

Yes, right. That’s the other thing: I created 100 AI videos, and I had 1 million AIs watch them. [laughter]

Erik Torenberg

And then I made a lot of money off YouTube. Exactly. I actually saw that video today of a YouTube farm where there are thousands of phones that just watch videos all day for some reason.

Ben Horowitz

Yeah, and that has zero value to YouTube advertisers. That’s actually a real problem for them. The whole creator-economy platform of the last decade—Substack, Spotify, and all the people who support artists, Patreon and other creators, YouTubers—they have a personal relationship with these people. It’s not just that they like the art. If they suddenly found out that they were bots, they might not want to support them in the same way.

Erik Torenberg

You might not want to give them a big YouTube tip.

Ben Horowitz

Yeah, I think there’s a certain subset of people who want to support actual people and feel like they’re having a real relationship.

Alex Blania

Yeah. The thing that I think people don’t really get is that this should be obvious, but I don’t think people really understand the consequence of it. What we currently experience is a super, super tiny glimpse of what’s about to happen.

Erik Torenberg

Yeah, right. It’s a glimpse.

Alex Blania

It’s a glimpse. The cost of intelligence is dropping almost exponentially, and agentic capabilities are increasing in some superlinear form. We currently see less than 1% of what it will look like in probably a year or 2. And, second, these things will actually be superhuman in many ways. They’ll be perfectly able to understand you and talk to you in exactly the right way.

Ben Horowitz

AIs are really good at programming humans. That’s much better than humans are at programming AIs.

Alex Blania

Absolutely. There’s no question. I think that’s going to get quite scary, also. But at least if you know you’re the victim of a psyop, or that it’s a very advanced one done by an AI, that would be extremely useful to understand. There was one paper that I think you’ve got to read. It was about the Change My Mind subreddit, where the University of Zurich did this thing where they had AIs actually interact with Change My Mind.

Ben Horowitz

Yeah.

Alex Blania

They were superhuman in their ability to change minds because they went back to the profiles of the people posting and understood their political motivations, the way they talked, and then interacted in exactly the right way. [laughter] They just hit all the buttons.

Erik Torenberg

Totally. Talk a little bit more about the state of the product and the business today. How many IDs are out there? Do you want to give us a little bit of an update and maybe talk about the evolution as well?

Alex Blania

First of all, it’s a multisided problem. I think there are roughly 3 things that you have to consider. One is that you need platforms to use the technology—things like Reddit, X, or things like that. You need distribution of these devices, and I think the right mental model for it is: how many minutes does it take a person to reach such a device, on average?

Currently, if you took the global average, it would be a terrible number. It would be days or something, because many people would need to fly. How do we get that down to below 15 minutes across the US? That’s probably roughly 50,000 devices that you need to deploy. It’s not crazy, but it’s also not nothing. It’s hard to do.

The last one is: how does all of that come together into something that a lot of people really want to use? That’s a combination of the utility of all the subplatforms, essentially, but all of that layers on top. Maybe you can use a new Reddit account. Maybe you get a certain amount of a ChatGPT subscription for free. I think it’s going to be a combination of things, but you need to land all 3 at some point at the same time, which is hard to do.

We’re now at 18 million verified users and 40 million in total in the app. The biggest thing is that, because of the past administration and because we use crypto, we didn’t really invest in the US for a long time. That’s now the main shift that we’re going through.

Alex Blania

Hopefully, we get the Clarity Act passed shortly.

Erik Torenberg

Yeah, exactly. It would be really great to get clarity on that.

Alex Blania

The big focus that we’re going through right now is to go all in on the US. Over the next year, 90% of the company’s effort is going to go toward the US. How do you get device distribution up? How do you eventually have this on every Starbucks, so it becomes super normal and people just use it every day?

On the platform side, we went through a very interesting experience personally. A couple of years ago, universally, people just made fun of us. That was the universal reaction, apart from a couple of other people who believed in it. In the press, the amount of fun being made of it just showed how shortsighted people are.

Ben Horowitz

That’s right.

Erik Torenberg

It’s like, you don’t think the bots are coming? What did you think when we first pitched it, actually? Even you must have thought, “This is crazy.”

Ben Horowitz

Well, because you had the Orb. The Orb was so wild. “Okay, we’re going to scan people’s retinas, and that’s how we’re going to know they’re human,” and so forth. You pitched us 6.5 years ago—6 years ago.

Alex Blania

Yeah, it was before COVID, because you were there with the Orb, right? AI just hadn’t happened yet.

Ben Horowitz

But you could kind of see that there were bots. They were very crude compared to what they are now, but it seemed inevitable. At least at the time, it was so far from the future that we always worry about the timing of these things. But you were impressive enough, it was going to happen eventually, and it was an exciting enough idea that all those things got us to say, “Okay, we’re in.”

It wasn’t obvious that it was going to work in that timeframe. It seemed very unobvious for a long time.

Erik Torenberg

How different was that pitch from what it ended up being? Talk a little bit about it.

Alex Blania

It was actually pretty much exactly the same pitch. I think it’s the same thing. The device changed; they made it much more economical and convenient. But the initial instinct was right. Basically, everybody is going to have to prove they’re human. You’re either going to have to have some proof that you’re human in cyberspace, or it’s going to be a very bad world.

Ben Horowitz

Yeah. I mean, the robots are going to get us. We’re done.

Alex Blania

Right. And the second point was that when it becomes a big deal, we’ll be able to build one of the most valuable networks as a result. In a world of AI, having a human network is going to be incredibly important. You’ll need to prove that you’re human, but it will also have very strong network effects.

Even as you get into platforms, one of the platforms’ largest problems has been bots. You remember Elon backed out of buying Twitter because all the stats were based on bots.

Erik Torenberg

Still, even knowing that, it was hard for them to get all the way to the future in their thinking and go, “Yeah, we need proof of human.”

Alex Blania

Yeah, it’s kind of obvious.

Erik Torenberg

People were like, “What does it even mean? What does proof of human even mean?” Did you have the language? When did you come up with the language “proof of human”?

Alex Blania

We actually had “proof of personhood” for the longest time. It’s even here in this brief. But then, at some point, we were like, “Well, at some point, AIs will have personhood, too.” So that’s not going to fly.

Erik Torenberg

Yeah, but they’re not going to have retinas for a long time.

Alex Blania

That’s actually—oh, that’s coming eventually. It was really funny. Some of the OpenAI people I met were like, “Man, Alex, this is going to be so dark. People will hate you for not giving personhood to AIs.” And I was like, “Jesus.”

Erik Torenberg

Let’s call it Proof of Human, then.

Alex Blania

That’s funny. So that’s how it changed. I would say last year, post-ChatGPT, there was a big shift. That was when AI suddenly got real to people. That’s when people started talking to us, but it was still, “It’s a future problem. It’s probably a couple of years out. We don’t really care about it. Let’s stay in touch.” That was the common response.

You also had a couple of CEOs who really believed that and were willing to take the long-term bet, to give them credit. But I think the second big shift was actually Cloud Bots and Mobile Book recently.

Erik Torenberg

Yeah.

Alex Blania

That kind of means the cow is way out of the barn. Honestly, if you don’t take it seriously now, then I think you should get a different job or something. You’re just not thinking about problems in the right way. That was the moment when many, many people started reaching out.

Now it feels much more like an execution problem, not a market risk anymore—not a market-risk or thesis problem. It’s just: How do you get 50,000 devices out there? How do you make it cheap enough? How do you make it economic? How do you make all 3 of these things work at the same time?

It’s still a very hard problem. How do you normalize the behavior so people aren’t weirded out in a Starbucks or something? Although, I think people are going to get used to that. I’m saying that because I think people will hate the alternative so much.

Erik Torenberg

Yeah.

Alex Blania

I think people are going to take a lot more pride in being human, by the way, particularly online.

Erik Torenberg

I think people are going to start getting accused of being bots.

Alex Blania

Totally. It’s going to get really weird. Without a clear delineation, it’s going to be a mess. I don’t understand how somebody can think they’re going to have a social media platform that doesn’t distinguish between humans and bots. That seems absurd to me.

Erik Torenberg

It’s absurd.

Alex Blania

My guess is that over the next 2 months, we’ll see these platforms trying to use things like facial biometrics on the phone. I know it will break, so it’s fine, but I think we’ll go through that cycle now.

We just need to get to scale fast enough to meet the market for what comes after, which I think means something like the Orb is the only solution. Currently, there’s no real competition. I have not seen a competitor yet, and I think we’ll also see that.

It’s so ridiculous. It’s so ridiculous, and it is so hard to get to in terms of building it. Then there’s a massive network effect, which means people are starting 6 years behind you on that. But I’m sure they’ll come, because it’s such an obvious problem now.

Erik Torenberg

What actually do you think about, as AI continues? What, in your mind, are the economic policies that we will need to implement, or directionally?

Alex Blania

I think governments do have to figure out how to send citizens money. They’re good at taking money from citizens, but not the reverse. If you go back to COVID and the stimulus program, I think $400 billion was stolen. You would have liked to know that you were sending the money to unique humans—even if they weren’t citizens. As long as they were unique humans, that would have been good.

Erik Torenberg

Yeah, I mean, the Social Security system, for example, is a mess in the U.S. It’s a total disaster.

Alex Blania

We’re going to have to get to some kind of cryptographically strong way to identify who’s a citizen of what country. That’s going to be a really bad problem, I think. Otherwise, there’s no way to even have a democracy.

It’s pretty crude what they’re trying to do with the SAVE Act, but it’s not completely insane. How do you even know that the people who are voting are actual people, or living people, or anything? We genuinely don’t know now.

The whole mail-in ballot thing is built for a very different world. I don’t think that, in an AI world where you can have high-scale impersonation, combined with a broken Social Security system, you’re going to have the will of the people anymore. I think that’s going to be gone pretty fast.

We’re going to need some kind of cryptographically strong infrastructure for who’s who. Similarly, I think we’re going to have to be able to get people money much more efficiently than through this crazy apparatus of social programs that we have, just because of how lossy and fraudulent Social Security, Medicare, and all of these things are.

Medicare is so frustrating for people that they shot the CEO of UnitedHealthcare in mail, and people are happy about that—really happy. Think about how bad a system that is. The government spends a lot of money sending you money for your health care, but it does it in a super-inefficient way.

We have the technology to do that now. I think AI is going to make that problem so bad because of the ability to file fraudulent claims and create fake, you know, buy social. I mean, you can buy Social Security numbers on the black market. For those who don’t know, that’s an easy thing. That’s a real thing. Everybody’s Social Security number is for sale.

Erik Torenberg

I agree with that.

Alex Blania

I think proof of human is a piece of a very important puzzle where we have to upgrade the entire infrastructure, or we’re not going to be a democracy anymore. That would be my guess.

Erik Torenberg

You said, “Okay, next year, go to market, focus on the U.S.” Say more about how you’re thinking about that. Is the incentive for people to do it because they get to use a set of services? Is there some other economic incentive, or how do you envision it?

Alex Blania

Basically, a month ago, we entered a very different phase as a project. I do believe many of the platforms that we’re now integrating with will bring a lot of users to our platform, and that changes how you think about it entirely. If you have a platform with a billion users sending users to you, then it’s really all about how you meet that demand. That’s what we’re now entering.

First, you will see—and we’re already working on it—a lot of really large platforms integrate in the near term. To set expectations, I think it will be slow initially, because it should be, just to understand the product. It will be focused on certain geographies. With Tinder, we started in Japan just to test the product and normalize the concept, but that will happen.

Secondly, one of my main priorities now is: How do you get Orb distribution up? Broadly speaking, there are a couple of different dimensions to that. First of all, the product needs to work at scale without supervision, which turns out to be much harder than you would think.

Every engineering problem at scale turns out to be much more complicated than you would think, because fighting for 1% of improvement in quality involves all these dependencies that come together. That’s one of the biggest engineering focuses right now.

But then, second, you need to find places to deploy them. The way to think about it is that there are large-scale distribution partnerships. That could be something like Walmart, or, if you’re very ambitious, something like Starbucks. Or it can just be one-off hip coffee shops, where you put it there. Eventually, you could even go to the DMV and put it right there.

So, that's the problem we're currently trying to piece together. It's going to be some of all of that. I think there's going to be some large-scale distribution partnerships and many one-off coffee shops.

Well, actually, one thing that we will launch soon—and the team is going to hate that I'm saying this now—but it's going to be Orb on Demand.

Erik Torenberg

Sounds good. [Laughter] Orb on Demand. Yeah, send it there.

Alex Blania

It's just because it's such a gnarly problem to get an Orb to truly everyone. The capex is insane. So, it's actually much cheaper and easier to put an Orb on a motorbike and drive it to you, as crazy as it sounds. In places like the Bay Area or New York, you will just be able to say, “Yeah, I want to verify now.” And 50 minutes later, an Orb comes to you at work and you can verify.

Erik Torenberg

Wow. Did you ever think about having different levels? Like, we know you're a unique human, or, hey, this guy may be a unique human because he's done it on his iPhone and it's not quite the same?

Alex Blania

Yeah, yeah, we have that. Generally, we have the principle that whatever could be useful for this problem, we just build it. We have something called Face Check that does that. It uses facial data from the camera. It still uses multiparty computation that we've built for the entire system, so you're still anonymous.

It of course reaches way less accuracy. As a system, you'll know something along the lines of, “Well, at least one person cannot create 100 accounts.” Maybe it's just 10 or 20, so it's at least some measure of rate limiting. I do think, just as a disclaimer, that with deepfakes and all this stuff, that will fundamentally break.

So, it's a temporary solution that I think can get us to scale. That's kind of how I think about it. We also use government IDs similarly, but just the ones that have an NFC ID chip. We use multiparty computation, so you remain anonymous, and platforms can choose to use that as well. But no one really did. Some of them have a very negative stigma, which I think makes sense.

Erik Torenberg

Yeah.

Alex Blania

But yeah, basically, whatever could do it, by any means necessary.

Erik Torenberg

That's right. Yeah. I don't know. Well, thanks so much for coming on the podcast. It's been great.

Alex Blania

Yeah. Thank you. Thank you. Thanks for having me.