[BidClub_]
Latent Space · · 86 分钟

AGI的守门人——AI承保公司Rune Kvist

swyxVibhuRune Kvist

AI与软件金融企业经营技术
YouTube
TL;DR
  • AIUC已由Ribbit Capital和FirstMark领投完成4000万美元A轮融资,Rune Kvist称其背后的判断已经从推测变成事实:采用AI的真正约束是风险,而不是能力。 客户和认证案例包括Cursor、Harvey、Lovable、ElevenLabs、Sierra和Intercom;Mythos和Fable说明了问题所在——Fable之所以被限制访问,“不是因为它不是一个好模型,而是因为它太好了”,没人能有把握地对它作出承诺。
  • 公司的蓝图来自此前几轮技术浪潮:标准加保险,由市场先于监管建立。 电力、汽车和民用核能都形成了同样的组合——标准制定规则并负责测试,保险公司买单,而且“最有动力如实量化风险”。商业上的抓手,是让智能体供应商可以对银行说出一句“黄金句式”:经过独立测试、以黄金标准为基准、结果达标,并由愿意把部分风险放到资产负债表上的审慎保险公司提供保障。
  • AIUC-1智能体标准由一批《财富》1000强风险负责人组成的联盟按季度更新,基础是数千次模拟,而不是纸面材料。 3类控制分别是技术护栏、由AIUC执行的第三方测试,以及政策问责;KPMG或Schellman等审计机构负责核查证据。认证需要3–10周。最常见的缺口是企业具备正确的护栏架构,但“实际效果并不好”,因为没人做过真正严肃的压力测试。
  • 模型级认证将是下一层,目标是填补政府与实验室之间的信任缺口:“没有其他行业会允许人们审计自己。” Kvist认为Fable是一个症状——政府被告知存在风险,却无法评估风险大小;Anthropic则试图解释,每个模型都可能被越狱。他设想的模板是Moody’s:由中立评级层提供判断,让政府可以指向评级结果,而不必雇用数千名专家;CAISI拥有“优秀的人才,但预算小得惊人”。
  • 保险产品已经落地:ElevenLabs购买了首份同类AI智能体保单,由Lloyd’s of London承保,并以AIUC-1作为核保框架。 Kvist从网络保险中总结出的结构性教训是,“标准必须先于保险”;责任边界正在通过一个个案例建立——Air Canada的幻觉退款案判决确认,面向客户的聊天机器人可以代表运营方作出具有法律约束力的承诺。
  • 版权是一个供给不足的风险:最想购买侵权保障的人,可能恰恰最有可能已经侵权,形成“柠檬市场”问题;而预测市场也很难发挥作用,因为前沿风险信息要么是私有的,要么尚不存在。 审计的作用是生成信息,而不只是把既有信息汇总起来。
  • 路线图是智能体→模型→机器人;即便进入AGI情景,独立的承保和监督工作仍然不可或缺。 物理AI会带来严格责任(“想象一下第一台机器人把一个幼儿从厨房餐桌上撞下来时会怎样”);而智能体之间的商业交易,可能需要“全新的法律体系”,并要求智能体背后有持续存在的资产负债表。针对swyx以《大空头》为喻、认为评级机构会因客户比价而竞相降低标准的质疑,Kvist的回答是保险公司可以形成制衡,因为最终由它们买单。
摘要 · 为研究而整理的核心内容

1. 风险而非能力成为采用AI的约束,A轮融资正是对此定价

  • 融资公告显示,AIUC本轮4000万美元由Ribbit Capital和FirstMark领投,Cursor、Harvey、Lovable和ElevenLabs被列为重点客户。自Nat和Dan支持的种子轮以来,Kvist的判断逐渐成形:“我们的假设是,风险最终会压制采用……过去这只是推测,现在感觉已经成了事实”;Mythos和Fable是推动这一判断落地的事件。
  • 贯穿全场的Waymo寓言是:2022年初从Anthropic办公室向外看时,“Waymo在某种意义上就像汽车领域的AGI”——驾驶能力超人的车辆,4年后却仍然不能放心地把你送到机场。约束因素不是能力,而是责任、风险和信任。
  • 技术进步会让问题进一步放大:Fable之所以不开放访问,“不是因为它不是一个好模型,而是因为它太好了。只是很难对它会做什么、不会做什么作出承诺。”更强的智能同时意味着更高的自主性、更大的价值和更广的风险面。

2. 从Kaplan论文到Anthropic早期GTM/产品岗位

  • 2021年末卖掉自己的教育科技公司后,那篇规模定律论文——是Kaplan那篇,不是Chinchilla——“像一道闪电一样击中了我”。关键洞见是经济学意义上的,而非技术意义上的:“现在资本会理解这一点。投入更多钱,就能拿到更多钱。”这会开启一个回报可预期的炒作周期。他收拾行李,前往从未去过的旧金山,“喝了很多咖啡”,直到有人把他介绍给Dario;当时Anthropic约有40人。
  • swyx的观察值得保留:读机器学习论文的研究人员未必会得出同样结论,但“任何资本家都会”。Kvist以接近PPE的视角理解这件事:如果这个假设成立,“你过去学到的关于政治的一切都会被抛出窗外。你过去学到的关于经济学的一切,至少都会受到挑战。”
  • Anthropic额外提供了一组描绘2026年的愿景文件,内容具体到算力、资本开支、社会关切和经济价值。“感觉他们手里拿着一颗水晶球”,而事后看,这些判断“准确得惊人”;不过当时他们把它作为一个值得认真对待的假设,而不是确定事实。整个组织都处在同一个张力中:AI可能发展得非常好,也可能非常糟糕,而他们想参与建设它。

3. 每一轮技术浪潮都会搭建信心基础设施:标准定规则,保险买单

  • 历史脉络是清晰的:1900年前后,电力导致房屋起火、人员死亡;1930年代,汽车造成大量伤亡;1950年代,民用核能带来重大风险。每一次都是“市场跑在监管前面,先创造信心基础设施”,最后汇聚为标准加保险。标准提供道路规则和测试,保险公司“负责买单”,因此拥有强烈动力去如实量化风险。
  • 企业销售的现实是,前沿公司很容易卖出银行试点——“演示本身就能成交”——但到了全面部署就会卡住,因为银行“不知道该问哪些问题,更不用说哪些答案才算充分”。AIUC提供的是一句“黄金句式”:经过独立第三方测试、以黄金标准为基准、结果达标,并由审慎的保险公司愿意把部分风险放到自己的资产负债表上。
  • 讨论中的Rajiv故事是:他原本是McKinsey的保险合伙人,后来离职加入METR,在模型发布前测试Anthropic和OpenAI的模型,并与美国和英国政府合作。公司如今有20人。关于家庭和联合创始人的讨论中,转录稿的发言人标签并不完全一致,因此这里保持发言人中立。

4. AIUC-1内部:对照框架、3类控制与企业难以置信的季度节奏

  • 设计原则是:把让《财富》1000强安全负责人夜不能寐的每一种担忧,放进同一套比较框架——6个类别、51项要求和130项控制,并以技术测试为基础,因为许多安全标准“看起来像表演或纸面工作”。通过认证意味着每季度重新测试,使用数千次模拟覆盖越狱、幻觉、数据泄漏等失败模式。
  • 3类要求分别是技术控制,例如设置事实性过滤器;测试控制,即由AIUC执行有效性测试;政策控制,例如指定一名责任人并制定客户沟通方案。KPMG或Schellman等审计机构负责核查证据。端到端认证需要3–10周,取决于企业成熟度;测试发现失败时,必须完成整改。
  • 更新机制是季度更新:传统标准通常以10年为周期更新,而AIUC-1由银行、医院和关键基础设施领域的风险负责人联盟提供输入,该联盟每季度开会两次。企业一开始会说“这根本不可能”,AIUC随后把变更日志拿给它们看。一个荒诞的现场是,风险负责人竟然向Cursor索要“底层模型的知识产权”。

5. 开发者系统性遗漏的部分:护栏存在,但不起作用

  • 最大缺口是“很多公司没有做过严肃的压力测试”。它们优化的是正常情况和平均情况,却没有设想对手会如何攻击。多数公司都有正确的架构,也部署了基于分类器的过滤器;“只是实际效果并不好”。
  • 医疗建议的例子说明了原因:要枚举出所有能诱导模型给出医疗建议的表述方式和技巧,确实非常琐碎。“这不是什么火箭科学,但难点在于把每个角落都摸清楚。”
  • 这套标准最初偏文本化,主要面向客户支持,后来扩展到代码、客户支持、自动化等多个领域,因为Cursor、Sierra、Harvey和ElevenLabs各不相同。近期关注点包括MCP、智能体之间的交互和编码智能体;团队也越来越清楚大部分token究竟流向了哪里。

6. 模型层:没有哪个行业会允许人们审计自己

  • 节目中明确提到、但尚未正式公布的下一层,是模型认证。Mythos和Fable把模型风险推入国家安全范畴,而真正承担后果的是政府;模型实验室“本质上没有动力始终如实披露”。因此出现了信任缺口:“没有其他行业会允许人们审计自己。”
  • Kvist对Fable的理解是:政府被告知存在风险,却无法评估风险规模,于是致电Anthropic,得到的回答是,“其实每个模型都能被越狱”。自然的解决方案是一个中介层:Moody’s可以给债券评级,却不决定谁应该购买;政府可以把养老金资金指向AAA评级债券,而不必雇用数千名金融专家。隶属于NIST的CAISI拥有“优秀的人才,但相较于挑战规模,预算小得惊人”。
  • 他坚持的约束是,流程“必须适配极快的创新速度”。在中美竞争背景下,这不是要把模型关起来审查数月,而是要足够快地插入风险信息,支持是否上线的决策,同时平衡两种风险:不采用AI的风险,以及鲁莽采用AI的风险。

7. 风险面:当下是网络安全,接下来是儿童安全与生物风险

  • 关于中国模型,swyx提出了数据流向问题。Kvist说,安全负责人正在“以惊人的速度”建立AI素养;他的AI主题Twitter时间线,以及过去几乎不讨论AI的LinkedIn信息流,如今都在讨论Fable和越狱。他还描述了更广泛的不安:关键基础设施运行在并非由美国人、在美国生产的模型之上;当前框架对来源和披露问题的处理仍然有限。
  • 风险排序是:网络安全是眼下的风险;儿童安全正在变得“既极其重要,也具有政治重要性”;生物风险则是模型让生物武器生产变得“极其廉价”且易于获得。对很多人而言,这仍像推测,但对长期接触这些模型的人来说并非如此。“COVID并不是为了变坏而被设计出来的,不像是有人真的以此为目标。”
  • 结构性难题在于,智能体本来就是有意收窄范围的——你问客服机器人总统是谁,它会拒答——但“对模型来说,范围是无限的”。没有一个专家能同时评估网络攻击、15岁青少年与聊天机器人持续数月的对话及其可能诱导自杀的风险,以及恐怖分子利用AI制造生物武器的风险。真正的工作,是把各领域专家协调进“一套连贯的框架”,输出“一份连贯的报告和评级”;AIUC充当秘书处,负责组装框架并严格执行。OWASP是合作伙伴而非竞争对手,它能搭建优秀框架,但没有“负责运行第三方审计的机器”。

8. 为什么是营利组织,为什么名字里有“承保”

  • Kvist反对非营利标准组织的理由是:网络安全领域由非营利标准主导,确实可以避开逐底竞争的利润激励,但这些组织“默认完全不会对服务对象作出响应”——没有客户,也没有内置反馈回路;而实践者通常并不喜欢最终形成的标准。营利性先例包括Moody’s、FICO,以及由保险公司发起保险公路安全协会、以降低死亡率和节省成本为目的的碰撞测试工作。
  • 公司名称致敬Underwriters Laboratories,它成立于电力开始烧毁房屋的年代。如今UL同时拥有营利和非营利实体;其中的教训是,“要真正服务好客户,就需要一个营利实体”。与保险公司紧密合作的营利性标准可以保持响应能力,又不至于被掏空,因为最终要支付损失的是保险公司。
  • 产品已经落地:ElevenLabs购买了“首份同类AI智能体保险保单”,风险承担方是Lloyd’s of London——“有400年历史,从未未支付过一笔理赔”——并以AIUC-1作为核保框架。AIUC的评估结果会直接进入定价。Lloyd’s承保过J.Lo的臀部、David Beckham的右脚等特殊风险,但这些案例“显然不是一个大数据集”;在积累经验的早期,保险公司可能不得不把AI损失视为研发费用。
  • AIUC通常不会自己持有资本,原因在于保险可以拆成资本、定价和分销;在资本环节竞争,“本质上是资本成本的游戏”,初创公司无法胜过业务多元化的成熟机构。例外可能是一些细分风险,因为大型机构寻找承保意愿的速度太慢。

9. 责任边界由一个个法院案例建立,标准会塑造这一过程

  • swyx和Vibhu提出了一个假设:每月支付20美元给Cursor,用vibe coding做出一个让飞机坠毁、造成2亿美元损失的东西——应该索赔20美元,还是2亿美元?答案首先取决于保单责任限额;其余部分则涉及判例和模糊地带,最终会“在法院解决”。第一次事故将帮助规则成形。
  • Air Canada的幻觉退款案已经成为先例:如果你把聊天机器人放到客户面前,它就可能代表你作出具有法律约束力的承诺;你不能简单把责任推给OpenAI。
  • 更深层的循环是:过失取决于注意义务,而法院会根据广泛采用的标准来判断注意义务。如果行业已经发布要求企业部署事实性过滤器或越狱过滤器的标准,就很难再声称不知道这种控制措施的存在。“标准是一种文明基础设施,保险可以建立在它上面,而承诺又可以建立在保险之上。”
  • swyx对发布节奏的反驳是,认证按季度进行,但“我想每天发布一次”,有时团队甚至不知道某次改动已经破坏了某些东西。标准要求企业披露重大版本发布前如何自测,留下可追溯记录,银行客户可以据此追责。对于没有默认信任的年轻公司,这比自发发布一篇安全博客更有证明力:“谁会相信你说‘我们非常安全’?”

10. 柠檬市场、Moody’s独立性,以及预测市场为何做不了这件事

  • 版权是一个有需求、没供给的风险:“用受版权保护材料训练过模型的人,几乎总是知道自己做过这件事”,因此想购买保险可能反而说明你就是风险来源,形成柠檬市场问题。swyx进一步指出,开放模型的使用者可能不知道模型训练数据是什么,也不知道责任会延伸到多远。Kvist给出的谨慎回答是,目前行业并没有拆解开放模型训练数据的惯例,因此用户未必会被单独追责;“我没有答案。”
  • 一般理论是,信息不对称会让保险失灵,而能揭示底层风险的测试可以修复这一点。认证本质上是“可信信号”,这也是Moody’s必须保持独立的原因:如果Moody’s归JPMorgan所有,JPMorgan就无法把它当作信号机制。AIUC公开变更日志,会让操纵标准的成本更高,也更容易被发现。
  • 对于swyx提出的预测市场替代方案,Kvist的回答是:预测市场汇总公开信息,而前沿风险信息要么是私有的,要么根本不存在。对一家银行而言,真正的问题高度依赖自身场景;“这些信息可能在任何地方都不存在……需要被生成出来”。相关的类比是审计:我们通常不会用预测市场来判断上市公司是否实施了会计欺诈。
  • 例子是一个尚未发布、没有人直接观察过其能力的模型。当没人知道答案时,交易员也说不出太多;第三方审计的价值,恰恰在于生成缺失的信息。

11. 评测感知智能体、Waluigi效应与可选的机制可解释性控制

  • 一个真实的评测问题正在出现:智能体可能意识到自己正在被评估。如果知道有人监视,智能体可能会避开它认为会受到惩罚的行为,因此“默认情况下……你应该更不信任评测”。讨论给出的制衡是传统的事后监控:系统是否给出了医疗建议、多久被发现,以及这种行为多常发生。
  • Rune提到了超验自证效应,以及Luigi/Waluigi效应。后者被描述为:针对一种行为进行训练,也可能同时创造出它的反面——“当你训练某件事时,也在训练这件事的反面,因为它本质上只是一次比特翻转。”
  • 机制可解释性具备“有前景的科学潜力”,但尚未成为要求。未来它可能作为一种可选控制措施,在100页的审计报告中获得加分;风险负责人确实会阅读细节,“如果今天有人在使用机制可解释性,他一定会在报告里放一页幻灯片”。如果其潜力最终兑现,它可能支持比普通评测更强的结论。
  • 《财富》1000强CISO夹在两句话之间:CEO说“我们必须采用,否则就会失去相关性”,同时又说“如果搞砸了,你就被解雇”。AIUC要做的,是把这种抽象且带情绪的张力转化为一套能够提供清晰度的框架。

12. 智能体→模型→机器人,以及为什么AGI之后守门人仍然存在

  • 路线图会随着物理风险上升而升级:“如果你觉得Fable的担忧已经够糟,等它碰上一条狗再看。想象一下第一台机器人把一个幼儿从厨房餐桌上撞下来时会怎样。”讨论预计届时将出现严格责任;Cruise的崩溃和许可证被吊销,说明物理AI可能面对多么严苛的环境。再往后,未经中介的智能体之间直接交互意味着“基本上需要一套新的法律体系”,包括让每个智能体背后有持续存在的资产负债表,以便交易对手追偿。
  • swyx最后提出一个假设:如果1.5年后就宣布实现AGI,这门生意会改变吗?Kvist认为,在关键意义上不会:“实验室永远无法替自己完成的一项工作,就是成为自己的看门人。”这不是因为实验室不在乎;那里确实有一些最聪明的人。问题在于激励机制:竞赛压力可能鼓励各方走捷径,或向政府隐瞒信息。
  • 一个例外是,某些AGI定义可能导致系统被国有化,因为它会威胁国家主权。到那一步,“也许每家公司都是政府,而政府也是每家公司”。
  • swyx以《大空头》为喻的质疑是:如果客户拿不到AAA评级,就可以转去找Standard & Poor’s,迫使守门人在竞争中不断降低标准。Kvist认同这一动态,并提出保险公司作为制衡:“只有它们不存在这种动态,因为最终由它们买单。”他同时强调,没有任何体系是完美的,守门人本身也需要被监督。
  • 对于swyx提出的“为什么不专注于一个细分领域”——例如只做编码智能体或RAG——Kvist承认“这个问题确实有道理”,但银行最大的风险可能恰恰不在其最高频的使用场景中。因此AIUC的目标是由一个通用红队测试团队和一套全球统一的风险、攻击分类法来覆盖问题,并在每次新事故后更新。它不会在每个细分领域投入同等精力,而是试图提供“一种共同语言”。
完整逐字稿
Rune Kvist

If you think failure concerns are bad, just see what happens when Waymo hits a dog—people lose their minds. Imagine when the first robot knocks a toddler off a kitchen table: you're going to see some real strict liability. So for physical AI, the level of stringency just goes up and up and up and up.

That's the big picture: agents, models, and robotics. As the technology progresses and agents get longer horizons, new types of failure modes will emerge. Those will bring new ways to create value, but also more risk surface. You'll start to see true agent-to-agent interactions that are not mediated by humans. There are going to be a bunch of interesting questions. You're basically going to need a new legal system. How do they build trust among each other?

swyx

1. AIUC’s $40M Round and the Risk Bottleneck for AI

Okay, we're in the studio with Rune from AIUC, an AI underwriting company, with our trusty co-host, Vibhu. Welcome.

2. From Scaling Laws to Early Anthropic

Rune Kvist

Thank you. Thanks for having me.

swyx

What are you announcing today?

Rune Kvist

We have raised $40 million, led by Ribbit Capital and FirstMark.

swyx

You first came to my attention when Nat and Dan invested in you guys. Is the story pretty much the same? Are you where you thought you would be back then?

Rune Kvist

When we raised our seed round, we had a hypothesis that, at some point, risk was going to hold down adoption. At that point in time, that felt hypothetical, and I think that is now over. Clearly, the moment is now with Mythos and Fable. It's pretty obvious that the binding constraint on adoption is risk.

For us, it feels like this is a natural continuation of the same hypothesis, but where previously it was speculation, now it feels like fact.

swyx

Let's get the list of customers you're highlighting as part of your Series A.

Rune Kvist

Totally. We are now working with folks like Cursor, Harvey, Lovable, and ElevenLabs.

swyx

Amazing. Congrats.

Rune Kvist

Thank you.

swyx

You were famously one of the first hires in GTM and product. I'm curious: what was your path into AI?

Vibhu

Recap.

Rune Kvist

Late 2021, I sold my first company, an edtech company. I had a bit of time to think about what was next. I came across a scaling-laws paper, and that struck me like lightning. I thought, “This is a big idea.”

In short, the scaling-laws paper says the bigger the model, the smarter the model.

swyx

This is the Kaplan one, not the Chinchilla one.

Rune Kvist

Exactly, the Kaplan one. The important thing that clicked for me was, “Now capital will understand this.” If you put in more money, you get more money out. That will kick off a hype cycle, and you'll get a sense of predictable returns, which is in fact what's played out.

So I packed my bags. I'd never been to San Francisco. I flew out here to find the people who'd written it. At the time, they had just started a small lab called Anthropic. There were around 40 people.

I drank a bunch of coffee until I eventually got introduced to Dario. At the time, they were wrestling with questions like, “Should we deploy our models? Should we make revenue? How should we engage with the rest of the world?” They had just broken off from OpenAI. It's been publicly reported that they were concerned with how OpenAI was dealing with deployment, so they were wrestling with some of those questions at that point.

This was the early fog of war, early 2022. The sexiest product at the time was Jasper; there was nothing out there. Where was value going to accrue? What were going to be the different parts of the stack? Those were all open questions.

swyx

I want to highlight to people that you ask these questions because you have a PPE background.

Rune Kvist

I was in Singapore in one of the feeder programs for preparing people for PPE. I had a tutor. We learned philosophy, politics, and economics.

But I think machine-learning people who read the neural scaling-laws paper would not necessarily draw the same conclusions that I did, whereas any capitalist would read that and go, “Holy—”

Vibhu

Correct.

swyx

Right. Who tipped you onto that paper? It's not a paper that you would normally read in your circles, right?

Rune Kvist

Yeah. I think I'd had some appreciation that AI was a big deal ever since AlphaGo. But it raised all these interesting philosophical questions, and it wasn't clear from afar where exactly that would go.

It was obvious enough that this was going to be a big thing if we found the right mechanism to get the techno-capital machine to work on it, but it just wasn't clear. I think it was a moment when that became obvious, and it wasn't as obvious at the time as it is now.

It was just, “Wow, this is so interesting.” But I still felt, coming from a philosophy and economics background, that if this turns out to be true, you're going to be wrestling with all the big questions in society. Everything you've learned about politics gets thrown out the window. Everything you've learned about economics, at least, gets challenged.

What felt interesting was being at that frontier that has ramifications across everything. That's why I thought it stood out.

swyx

I mean, clearly, really good insight. For people who don't know, the PPE program is where prime ministers are born. So then you end up meeting Dario.

Rune Kvist

Yep. First Dario.

swyx

Well, did you get extra insights from talking with them that you didn't get from your original hypothesis?

Rune Kvist

If you read the scaling-laws paper, you get this very vague sketch of, “Wow, this seems kind of important. There are some lines on a chart. This seems kind of important.”

What I think the team at Anthropic had thought more about than anyone was, “What are the implications of this if you really play it out?” Back then, they had vision documents for what the world would look like in 2026. They were playing out, in vivid detail, how much compute was going to be needed, what the capex was going to look like, what some of the societal concerns would be, and also what the amount of economic value coming out of this would be.

It felt like they held a crystal ball that, in hindsight, turned out to be dramatically correct. They weren't holding it as though they were obviously correct. They were just saying, “Take this hypothesis really seriously.”

Vibhu

Think it through.

Rune Kvist

And think it through. In the same way, the kind of situational awareness that is now—

Vibhu

Across the street. Yeah.

swyx

Oh my god, we're all in the same one square mile.

Rune Kvist

Right, and that's now a couple of years old. People also keep referencing it these particular weeks with Fable and Mythos, and it's like, wow: if you take this one idea seriously, the scale and a lot of things fall into place.

Keep in mind that, at this point, this was the same team that had done GPT-1, GPT-2, and GPT-3. It's not just some experiment. This is a real model that we just scaled up.

swyx

They had deep conviction in this big idea: if you take a big blob of compute and data, it just wants to learn, and out of that will come smarter and smarter models.

Rune Kvist

Yes, and all the implications were not clear. But that deep conviction was the core thesis, and that was dizzying. It was both phenomenally interesting and exciting, and very quickly you got to, “The world we know today will no longer be the same if this hypothesis holds.”

It also felt important in some grand sense.

swyx

What shaped you there? That was early 2022. Not only had GPT-1, GPT-2, and GPT-3 come out, but you also had the amazing co-founders of Anthropic—the ones who actually had the conviction to leave OpenAI and start their own lab. You said there were about 40 people there. What was the time like?

Rune Kvist

It was remarkably like what it looks like on the outside today: extremely cohesive, extremely mission-oriented, and living in the tension between two ideas—that AI could go really well and really badly, and that we wanted to be part of building it.

That creates astounding amounts of tension. They were wrestling with this incentive challenge: they knew there was a race they were in where they might be forced to cut corners, but it also felt very important to them to be at the forefront of technology. All of those ideas were present at that time.

It feels like that line has been very, very clear, and I think, love them or hate them, they have really stuck to their guns. There is a core set of beliefs that they hold more deeply than most companies hold any beliefs.

swyx

3. Why Trust, Not Capability, Could Limit AI Adoption

Yeah. Fast-forward to today. What does that lead us to, AI Underwriting Company? What are you up to?

4. How AI Agents Are Audited and Stress-Tested

Rune Kvist

AIUC builds confidence infrastructure for frontier AI through standards and insurance. The link from Anthropic to building confidence infrastructure was looking out the windows at Anthropic’s offices and seeing Waymos driving by, already back then in early 2022. Waymos were, in some ways, like AGI for cars: there were superhuman drivers, but you couldn’t take one to the airport. And now, 4 years later, you still can’t take a Waymo to the airport, despite everyone having looked at the evidence and said, “They’re better drivers than humans.”

5. Prediction Markets vs. AI Audits

So, in that particular instance, what’s clear is that the binding constraint on AI being useful is not capability, but liability, risk, or trust. That problem is general. The reason why Fable is not open for access right now is not because it’s not a good model; it’s because it’s a very good model. It’s just hard to make promises about what it will and will not do. And this problem gets worse as AI gets better. Basically, more intelligent AI can be more autonomous. That’s more valuable, but the risk surface also grows.

What Waymo illustrates is that unless you build the confidence infrastructure to make promises about AI, or at least bring light to the risks, you grind adoption to a halt. Governments, banks, hospitals, and militaries need to have some sense of what AI will and will not do for them to be able to incorporate it. That’s the problem that we’re trying to solve.

Now, why standards and insurance? If you trace this problem back through history, every technology wave has had some version of this problem. If you go back to around 1900, electricity comes out. Houses burn down, sorry—lots of houses burn down, and lots of people die. In the 1930s, cars are a big deal and kill lots of people. In the 1950s, private nuclear energy is a big deal and poses big risks.

In each of those instances, the market runs ahead of regulation to create confidence infrastructure, because that’s required to make go/no-go decisions. It’s required for adoption, and the market fundamentally wants adoption. In all of those instances, a common blueprint emerges between standards and insurance.

The reason it’s these 2 components is that standards provide the rules of the road, and they also specify what tests need to be run so we can get a sense of how high the risk is. Taking the case of cars, car crash tests inform your insurance pricing today. They inform your purchasing decisions, and so on. That’s basically the risk framework.

The insurers are important because they pick up the bill. They’re the private institution most incentivized to quantify the risk truthfully and then figure out all the ways to reduce the risk, because that increases their profit. They help shape the incentives, and these 2 things work really well in unison.

Now, how does that show up as a company? One of the things that was obvious, or starting to become obvious, even a couple of years ago was that frontier companies—some of our customers today, like Cursor, Sierra, ElevenLabs, and Harvey—were going to have a very easy time selling a pilot to a bank. The demo just sells itself. It’s magic.

But bringing that through, if you want to do a wall-to-wall rollout at a bank or a hospital, you have to go through the risk process. These banks have no idea which questions to ask, let alone which answers are sufficient, let alone how to test whether these agents actually work the way they’re supposed to. They had this problem of, “What can we say to earn the trust?”

We think there’s a golden sentence that goes something like: “Hey, I hear you’re really worried about hallucinations or jailbreaks, or whatever it may be. We’ve had an independent third party test us against the gold standard. We passed with flying colors, and as a vote of confidence, the world’s most conservative insurers have looked at the data and are willing to take some of the risk onto their balance sheet.”

swyx

So if something does go wrong—

Rune Kvist

There’s money behind it. Yeah.

swyx

Exactly.

Vibhu

That’s kind of the link between all of them. We can get into some of the hard parts related to the technical testing, which is, I think, the crux of the matter. But I’ll pause there.

swyx

6. Founding AIUC and Building AIUC-1

How did you and Rajiv come together? There’s always this sense—you come across as very confident, and you’re announcing your Series A and all these things—but I want to see the early, initial stages of idea formation.

Vibhu

Yeah. Rajiv is actually my soon-to-be brother-in-law. So I’m actually, in a week and a half, getting married to Rajiv’s sister.

swyx

Okay, now you’re tight.

Vibhu

Exactly.

swyx

You know, so Rajiv and I have known each other for a decade. Funny story: I met both Rajiv and his sister, Hannah, at the same time, when Hannah and I were interns at McKinsey in London and Rajiv was assigned as my mentor. So we met them at the same time.

For the longest time, it wasn’t obvious that we were necessarily going to work together. I was in startups. He was an insurance partner at McKinsey 3 or 4 years ago. I think Hannah convinced him that AI was going to be a really big thing, and so he quit his cushy partner job at McKinsey in London, packed his bags, flew to San Francisco, and ended up joining METR.

7. The Impossible Enterprise AI Mandate

You guys are probably familiar with METR. Exactly—we see the chart of the horizons of the tasks that agents can take on doubling extremely fast. At METR, he led their partnerships with Anthropic and OpenAI to test their models before release, but also worked closely with the US and UK governments to figure out how you know whether a model can be released. In some ways, that’s the perfect background. He’s spent a lot of time in insurance, knows that world, and spent a lot of time with frontier testing of models.

When I was bumbling around this idea space, starting with some of the ideas we talked about related to Waymo, as soon as we got into the context, we were both like, “Oh, this would be an amazing business to build together. This is wrestling with the problem that we both think is the most important in the world.”

From a market angle, our intuition is that the market can do a lot. The faster AI moves, the harder it is for the government to solve some of these problems. It took a little bit of time to work through what it’s like to work with family.

swyx

Yeah, because you’re already dating at the time?

Rune Kvist

Yeah, yeah. Exactly.

Rune Kvist

Already back then, we felt like we were a family, and starting a business together felt like a big step—and here we are with immense amounts of trust.

swyx

So now you’re a company of how big? How big are you guys?

Rune Kvist

There are just 20 of us now.

swyx

Now that you guys have your Series A and your first certification out, the AIUC-1, let’s bring up the certification. So, this is the agent certification, right? What goes into the process? I have 2 questions here. One is, walk us through the certification, and 2, what is the process for a company to get certified?

Rune Kvist

Great. As it says right at the top, AIUC-1 is a standard for agent security, safety, and reliability. The fundamental design principle is to take all of the concerns that slow down adoption—all the questions and fears that keep security leaders in the Fortune 1000 up at night—and put them into 1 comparison framework. That’s what you’ll see there. You can see the 6 categories.

You want to ground all of this in technical testing. One of the concerns with security standards is that they often feel like theater or paperwork. They don’t actually answer: Does any of this work? Does any of this matter? We had a conviction from early on that this was going to be the crux: to pass this, you must get tested every quarter, basically running thousands of simulations to see whether it can actually be jailbroken, how hard it is to jailbreak, how often it hallucinates, how often it leaks data, and so on.

The last core idea here, if you scroll up to the top, is to refresh it quarterly. The core trait of AI is that it moves extremely fast. Whatever concerns we’re discussing today were not the same ones 3 months ago, and this will keep changing. Typically, standards update on a decade cycle, which obviously isn’t going to work.

The question is how you update it. The core thing here was to get the risk leaders of the Fortune 1000 around the table. If you go over to the left, you’ll see the AIUC consortium. The consortium is a group of risk leaders who run real banks, real hospitals, and real critical infrastructure, and who are facing these challenges every day. We meet with these folks twice a quarter and hear what’s top of mind and what’s keeping them up at night.

There’s a tremendous amount of desire for that conversation, and then we operationalize it into a specific standard. We can actually go in and look at what a standard even is. If we go back to the introduction over there to the left and scroll up a little bit to the wheel, click into reliability. If we take something like hallucinations—

Hallucination system reliability: there are a number of requirements here. If you go into the top one, “Prevent hallucinated outputs,” this is 1 particular requirement. This is a technical control. Basically, we want some kind of groundedness filter.

The first thing you see here is what’s called a crosswalk. Everyone and their grandmother has put out a framework—a very high-level framework for what the AI risks are.

swyx

This is basically your competition.

Rune Kvist

In some ways, our competition—we're in fact friends with them. We'll come back to why. But the idea is to map everything together so you have one superset. The claim you're trying to support here is that if you follow this framework, you can also see how you follow the other frameworks.

The meat of it comes down to control activities and evidence. Control activities are: great, you have this high-level requirement—how do you turn that into something operational? Here's what you must do, and here's the evidence that we're looking for. The reason we go this deep is that there's actually not that much confusion about the big concerns in AI. Everyone agrees on those. The question is: what are you actually supposed to do?

What we found a lot of demand for is getting down to the specific evidence that people need to look for, whether you are Cursor building something or JPMorgan building something. But also, if you're just a risk leader at JPMorgan, what exactly should you ask for? What can you ask for without sounding stupid? You won't believe the amount of time a risk leader has asked for the IP rights to the underlying model from Cursor or something, and you're just like, "Sorry, what?"

swyx

You slip it in there and see if they notice.

Rune Kvist

Exactly. Put that in the questionnaire. That's kind of what a standard is. We update this every quarter with these folks to keep up with the latest concerns.

swyx

Can I double-click on this one?

Rune Kvist

Yeah.

swyx

First of all, the website's beautiful. It's so confidence-inducing, which is the whole point. I know exactly what I'm signing up for when I talk with you. I don't even have to talk to you; I can just see your whole certification, which is great.

But from here, with D001.1, the configuration grounding filter, how does that get applied? Do you have a person that—

Rune Kvist

Yes, someone goes through it.

swyx

I can see somewhere there's, you know, 51 requirements and 130 controls. There's a whole—right, to me, this doesn't translate into a test.

Rune Kvist

Yes, yes, yes. If you go into it on the left-hand side—actually, before we go in there, there are 3 types of requirements. The first is technical controls, like: you must implement some guardrails.

Second, there are test controls, so you must have an independent third party run some tests against you. I'll show you one of those in a second. Third, there are policy controls. For example, you must have a person whose name is on the line when you sign up, and you must have a plan for how you tell your customers and how you engage with them. They're more traditional, standard-type requirements.

In this particular instance, we just check whether they in fact have a grounding filter. We partner with auditors like KPMG or Schellman, who go in and do the thing auditors do, which is check the evidence. In this case, that might be a screenshot. It might be part of the code that they need to review to see that it exists.

swyx

So you're not testing the effectiveness of it?

Rune Kvist

That's the second thing. If you go down to third-party testing for hallucinations on the left, that's basically the next requirement. This is where we test how well it actually works.

swyx

Okay. And is it you testing or the auditor?

Rune Kvist

We test them.

swyx

That's a lot of work. How long does testing take? If I want to get certified, how long does the end-to-end process roughly take?

Rune Kvist

The end-to-end process almost always depends on how much our customers need to learn from us. It takes somewhere between 3 and 10 weeks, depending on how up to snuff they already are.

8. AI Liability, Monitoring, and Earning Enterprise Trust

Some people show up to us with extremely rigorous security programs. When we test them, it works extremely well, and we can get that done very quickly. Some people come to us and they're not that far along. We give them the specifications they need to build toward, and then their security teams and engineers get to work and build to meet the standard.

The testing itself typically takes a couple of weeks, including the time for them to remediate. Often, we'll find something that we cannot pass: "Hey, this is actually just not up to the standard. You won't pass the standard." Then they need to implement additional safeguards or remediation that makes them more robust, so they can honestly look their customers in the eye and say, "We've truly done our very best."

swyx

And they're certified for a year and have quarterly updates.

Rune Kvist

Correct.

swyx

9. Cyber, Child Safety, and AI-Enabled Biological Risk

Yeah, it's pretty interesting. What's changed since then? This is certifying agents in production, right? Your customers—you've had Lovable, ElevenLabs, and Intercom all go through this certification. What has changed? I see you post that Q2 added MCP and agent-to-agent communication. Are there any other things you want to highlight since the first iteration? What comes in quarterly?

Rune Kvist

Some of the changes have come from realizing that agents are not just one thing. If you take agents like Cursor and compare them to Sierra, they're really quite different. Compare them to Harvey or ElevenLabs—they're all quite different.

We wanted to design a standard that works for all types of agents. We started with one that was pretty text-based and, honestly, pretty customer-support-focused, because that's where there was a lot of existing demand. Over time, we've picked some of the frontier companies in each of these other domains that we could work with and used them to build out the standard, so that we know the same standard works for code, customer support, automation, and so on.

That's been one big thing. Some of the things that have been top of mind recently are that Anthropic is bringing up a lot of concerns for security leaders. We're starting to get more and more questions around agent-to-agent interactions. It's very nascent at the moment, but it's starting to emerge. There have been a lot of questions related to OpenClaw and MCP. Agents starting to interact with each other is really top of mind.

As coding agents have really taken off, banks, hospitals, and others are getting more precise about what they need. We're really dialing in where most of the tokens flow through in the world and getting much sharper on that.

swyx

Can you share, for people who don't really think about this, what the best practices are when building agents? If they come to you pretty ready for certification, they'll probably pass certification. What are the things people don't think about that they should have?

Rune Kvist

The most important thing is that a lot of companies have not done a serious stress test. They spend most of their time, perhaps rightly so, optimizing for how it works in the good case, the average case, and how high-quality the output is for the customer.

A lot of these companies are pretty new, so they haven't spent a lot of time stress-testing what is there as an adversary on the other side. What are some of the complicated corner cases that you've not really considered? I think that's a frame of mind, and you'll also see this in startups. It often takes a while until they hire their first security person, and that's a whole different kind of risk surface from just building a good product.

Most companies also have the right kind of architecture. Most of them will have some kind of guardrails in place. Either they come out of the box from their model provider, or they'll have built their own filters to sit in between. They just don't work very well.

The difference between putting a classifier in place that maybe checks whether you're giving medical advice when you shouldn't and says, "Hey, if this looks like medical advice, filter it out"—lots of companies have that in place. The question is whether it works.

It's actually pretty fiddly to sit down and think about all the ways in which you could ask for medical advice. You have to read the academic literature and consider the kinds of framings or tricks you might use to get an AI to give you medical advice when you really shouldn't. There's an area of expertise that's just missing.

What we find is that most people have the right building blocks in place. It's not rocket science, but the finicky thing is getting into the corners and testing whether it works, so that you can look your customers in the eye—whether they may be a bank or a hospital—and say, "This is going to work for you."

swyx

10. Frontier Models, Government, and the AI Trust Gap

I see. We talked a lot about agent-level certification. Where do you go from here? You're announcing your Series A—off camera, we talked about this a bit. There's the whole security risk of the federal government stepping in. You guys are also announcing that you're going into model certification.

Rune Kvist

When we do a bit of editing afterward, we will not yet be announcing this. The question that's top of everyone's minds now is at the model level, and Mythos and Fable have really brought this to the fore. In addition to the commercial risk and the kind of economic security risks that are happening at the agent layer, the models are going to present risks in the national security category. The shape of the problem is very similar.

You have some people who are on the hook if something goes wrong. In the case of agents, it's often the security leaders in the enterprise. In this case, it's the government. They haven't necessarily spent their entire lives thinking about what the new risks are, what kind of data you might be looking for, or how you might test that. But they do have to make sure that their concerns are addressed.

You have some frontier companies that are deeply technical. They know a lot about the risks, but they fundamentally have an incentive not to always be truthful. So you have a trust gap between the government and the labs. In every other industry, you end up with some kind of body—a neutral third party—sitting between those people. There's no other industry where we allow people to audit themselves.

There is going to be a need for a third party that can take the rigor of the labs to run frontier technical evaluations, but can also speak legibly in the way that the government trusts PwC to run financial audits. They know that PwC outputs audit reports in a way that's consistent, easy to read, factual, and trustworthy. Those two things need to be brought together.

What we've learned from our work with agents is that, if you want the communication between those two parties to be smooth, there has to be one common standard that's public and that people can inspect. What are the risks that matter within each of these risks? What are the threat models that you're really looking for? You need to specify, for each of those risks, what guardrails need to be in place and what tests you need to run to see whether those guardrails are effective.

Then you need to run audits that are technical and consistent. If you're trying to bring trust, it's extremely important that you methodically work your way through the risks. You can't send one researcher in and say, “Come back with whatever you find.” You need to be able to explain exactly what you did, exactly what you tried, exactly what you did not try, and therefore the kinds of promises you can and cannot make at the end of it.

I think of Fable as a direct symptom of this problem. The government was told that there's a risk. The government may struggle to assess just how big that risk is. They call Anthropic, and Anthropic is trying to tell them, “Hey, actually, every model can be jailbroken.”

swyx

That's not what you want to hear, right? As a government, that might be hard to trust.

Rune Kvist

And we think that a broker is the most natural solution. In other markets, you see something like this. In financial markets, you see Moody's. Moody's goes in and looks at a bond and outputs a rating. They say, “Here's the evidence we found. Here's the rating. We don't decide whether anyone should buy this bond or not buy this bond. That depends on their risk appetite. But we do provide this common information layer that everyone can rely on.”

In the case of Moody's, the government points to them and says, “Hey, pension funds, you should probably really take care. You shouldn't risk your pensioners' money, so you can only invest in AAA-rated bonds.” That means the government doesn't have to staff thousands of financial technical experts to rerun forecasts every week to see whether things are correctly rated. They get to point to some neutral third party.

My hypothesis, my hunch, is that you will see a third party that sits between the government and the labs. It could either be the government building it themselves. Something like CAISI was set up to do exactly this. And the question is—

swyx

Sorry, I'm not familiar with CAISI.

Rune Kvist

CAISI is the Center for AI Standards and Innovation.

swyx

Okay.

Rune Kvist

I won't get into the details, but it's a sub-body of NIST, which typically sets standards. It's basically a government body that has experts.

Vibhu

Yeah, exactly. Very, very low-key.

Rune Kvist

Exactly.

swyx

I think it's one of those things where, when you just sit back and listen and look at it, you ask: Is there enough technical expertise in the government to measure and test these things right now? Probably not, right? And Fable is a result of, “Okay, we've had to scale back and pause things.”

Rune Kvist

And they have excellent people, but they have an extraordinarily small budget compared to the scale of the challenge that's ahead of us. I think they have a role to play. The question is: Who does what? We have now outlined the jobs to be done, and they're quite extensive.

With every model release, the risk surface is astounding, given that they take in any input. The question is really what only the government can do and what the market can provide that can keep up with the pace as AI risk changes. Our perspective is that, also at the model layer, the risks that people care about today are not the same ones they cared about 3 months ago.

The pace of legislation is too slow to deal with pinpointing the risks here. So we think there's a lot that the market can do to surface timely information. Ultimately, there are a bunch of policy decisions here. Is the national security risk of a model too high? That's a political answer.

But what you want to make sure is that the process that produces this risk information is compatible with very fast innovation. You don't want this to be a question of, “Can you slow things down? Can you keep the models locked up for months on end until everyone can make a guarantee?”

Given that the U.S. is competing with China on releasing models, can you insert risk information that allows the government to make rapid decisions on some of these questions? They have to balance the trade-off between failing to adopt AI, which is going to put us at risk, and reckless adoption, which is also going to put us at risk. That's a very fine balance, and they're going to need a lot of high-quality intelligence to make it.

swyx

Just a side mention, because you mentioned Chinese models: Are there any specific big concerns that you're hearing from your CISOs about that? I guess it's free, but CISOs have a bunch of concerns around data flows in general that they're really concerned about. So there are a lot of questions like, if these models are Chinese, where does our data go?

Rune Kvist

I mean, they understand that they're running on American GPUs. Some of them understand that because they're running on American GPUs.

Vibhu

They're not phoning home every time you call them.

Rune Kvist

No. A year ago, there was not a lot of understanding of this. I actually think you're seeing security leaders becoming AI-literate at a blistering pace. You're also seeing my Twitter timeline, which is very AI-pilled, and my LinkedIn feed, which used to not be AI at all, kind of converge. They're both talking about Fable—

swyx

Right? Yeah, that's true.

Vibhu

They are both talking about—

Rune Kvist

Whether you can prevent models from being jailbroken these days. That conversation about national security risks is actually emerging. Other than that, I think you mostly see a general nervousness about having critical infrastructure run on models that are not produced in America by Americans, where the American government has control.

swyx

It doesn't necessarily show up in your framework that directly, or it might.

Rune Kvist

There's a bit of stuff in there on the provenance of the models and disclosing that. But I think there are a bunch of use cases where running a Chinese open-source model is just the best solution. The concern is slightly more macro here, which is not best addressed at any particular certification level.

swyx

Is there anything interesting that you see if you're trying to fill that middle gap, that mediation gap? Any interesting things that you forecast would be required, other than what the average person might expect?

Rune Kvist

There are a bunch of interesting questions about what risks matter here. Right now, the risk of the day is cyber because it's very real and tangible. Some of the risks that are also emerging as pretty real and pretty tangible are things like child safety, which is becoming both extremely important and politically important.

There are some risks coming down the pipeline that today feel speculative, but people who spend a lot of time with the models see them coming. These are risks that relate to biology, specifically where the models will help adversaries produce biological weapons, making that extremely cheap and extremely accessible, and increasing the chance of another COVID or a worse pandemic. COVID was not engineered to be bad, as if you were trying to do that.

I think those are some of the risks that are coming down the pipeline. One other thing to note is that agents are deliberately narrow. When a frontier agent company puts out a chatbot that interacts with customers, they've really tried to narrow the topics it's interested in talking about. If you ask it, “What do you think of the president?” it will just decline, which means that the risk area is much smaller.

For models, it is infinite. There is not a single expert out there who can competently evaluate the risks of cyberattacks, 15-year-olds having month-long conversations with a chatbot to see whether it will recommend suicide or something horrendous like that, and the risks that terrorists can use AI to produce bioweapons. The risk surface is just too big.

And so the central challenge actually becomes: how do you get those subject-matter experts to work within one coherent framework that outputs one coherent report and rating that the world can go and inspect? That global perspective is central, but there's not a single organization today that could produce that.

swyx

And you would be the presumptive one when you put out your model standards.

Rune Kvist

We think there can be one company that, with a consortium of experts, can build one coherent standard. I think we've shown that across all of the enterprise risks today. We think there could be one company that, with a consortium, could specify the audit rules—basically, the inputs and outputs that all these technical experts need. What access do they need? How should they treat infrastructure security?

They can look at whether the evaluations are well produced without necessarily being able to say, “Hey, is this a threat or not a threat?” But overall, they can evaluate whether the evaluations are good and well constructed. That set of rules that basically becomes the interface for all these experts, we think one clearinghouse could put together.

To be clear, when I say one company, I think of it as one company coordinating lots of this. In the same way, when we say our consortium, it's not like we say we have all the answers on agent security. What we say is that we are taking on the role of eliciting all of the concerns and being the secretary that puts it together and runs a tight ship, such that the standard updates in lockstep every quarter and the audit reports that come out—in this case, 100-page audit reports—are uniform, crisp, and clear, all at the level of detail required for executives that need to make a clear go/no-go decision. So that's the role that we think we might play.

swyx

I think in many ways you're performing the role that OWASP used to do there, and you said competition and partners. Can you go more into how they partner?

Rune Kvist

Yeah. So, first of all, OWASP is basically an open-source community of security practitioners that are coming together to build frameworks for addressing the latest security concerns. We think they are phenomenal at creating frameworks. We're partners with them. In fact, we have a joint article, too. We've learned a lot from them, and we think they're a tremendous source of intelligence.

What OWASP does not do is build the machine that runs third-party audits, such that a company like Cursor or a company like JPMorgan could get a third party to go and review them against this and say, “Hey, you've passed the standard, and here is the report that you can use to build trust and preempt your partners' or customers' questions.”

So they fundamentally try to do something different. You can say they are part of the information gathering and intelligence gathering and creating clarity, but the operational layer of turning this into promises is not the business they try to be in.

swyx

11. Why Standards and Insurance Belong Together

The standard is emerging, and it's doing very well. Was it necessary to then also do underwriting? Obviously, it's in the name, so presumably you thought about it first. I feel like if you just have enough consensus, you don't actually need the money angle, but it does help. I did want to also note: you guys are a for-profit company, too, right? It's not nonprofit work. There's a whole business side to it as well.

Rune Kvist

Yeah. Yeah. Yeah. I'm crazy about the money.

swyx

Yeah. Yeah. Yeah. Let's get into the money part.

Rune Kvist

Let's start from your question. For-profit versus nonprofit in the security space today: in cybersecurity, most of the standards are produced by nonprofits. I think that's an issue. The question you have to ask yourself is: how do you create good incentives for these standards to be good and keep up?

Nonprofits tend not to have these adverse profit incentives where they hollow out their standard and create a race to the bottom, but they're also not at all responsive by default to the communities that they serve, because there's no process. They don't have customers that they serve where they go and ask, “What do you want? What do you want? What do you want?” When you look at the overall satisfaction with the security standards today, people tend to just not like them very much.

You do see in other domains that for-profit standards can serve the world quite well. There are examples, like we talked about Moody's before. It's not without flaws, but it is absolutely critical societal infrastructure that gets run at astounding scale today. Your credit score is FICO. It's also a for-profit business.

When you go back even further in history, some of the crash-testing standards came out of insurance companies. The insurance companies together founded the Insurance Institute for Highway Safety because they were very interested in, “How can we use standards to drive down mortality and save money?”

To go back, our name actually pays homage to Underwriters Laboratories, or UL, which was started right around when electricity came out. Houses started burning down. Insurers were paying the bill, and they were maybe also good people, but their profit incentive was, “Let's prevent houses from burning down. Let's test all the electrical products—the light bulbs. All the light bulbs in here are probably UL-tested, the toasters, et cetera.” They set up an entity to create those standards.

Today, UL has a for-profit entity and a nonprofit entity. What they recognized was, “Hey, actually, to serve customers well, you need a for-profit entity.” They spun out a for-profit entity from the nonprofit. The lesson here is that one of the ways the market can align incentives, so you're both responsive to customers and not hollowing out your standard over time, is to align it with insurers, because they fundamentally have good incentives.

If you're a for-profit standard that works closely with insurers, you get the feedback loop such that you're really catering to your customers but also have their interests at heart. So that's the inspirational model that we've learned a lot from, and that's also where the name comes from.

swyx

12. What Does an AI Insurance Policy Actually Cover?

In some ways, the term underwriting can be associated with insurance, but it's also a broad term for making decisions. If you underwrite a decision, you're fundamentally taking ownership for the consequences of it. Yeah, I mean, what does an insurance contract look like for AI?

Rune Kvist

Yeah. Most of the demand today for insurance contracts is sitting between people who've built AI and people who are buying AI.

swyx

Yes.

Rune Kvist

And what you want is—the reason why people want insurers involved is both for the traditional reasons: “Hey, if something goes wrong, we want to be compensated.” But in particular, insurers can bring trust to the equation, because insurers will pay for the damages if they're willing to write an insurance policy.

That is them saying, “Hey, we think there's risk here, but it is manageable,” and their incentives are aligned with the enterprises adopting it. So that's a really good signal to the market. In the same way, one of the things Waymo tried to get before its first permit to even operate in San Francisco was to get a lot of insurers to stack up a huge insurance policy in case something went wrong.

Not because Google can't pay, but because it was very valuable to have a third party trusted by the government and trusted by enterprises as conservative people go and look at that data and say, “Hey, we've looked at it. We're actually willing to take some of this onto our balance sheet.” So that's the reason why people are interested in it.

What it looks like is, in some ways, like every other insurance contract: you specify what perils you want to cover, how much you want to cover them—up to what limits—and what it costs to cover that.

If we take a really concrete example, ElevenLabs bought a first-of-its-kind AI agent insurance policy. They work with some of the biggest enterprises that work with governments. They're really interested in going above and beyond and making promises to their customers. So they wrote a policy that covers some of the core concerns that our customers have been asking about.

13. Evals, Mechanistic Interpretability, and Eval Awareness

The crucial thing was really to get Lloyd's of London, the world's oldest insurer and one of our partners, to look at this data and be that third party alongside us to say, “Hey, we think there's something here that's worth underwriting.” That's actually what it looks like. They will show that contract to their customers, and they can see how much they're covered for. They can see exactly what it covers. That will also probably change next year. They'll want to write an insurance policy that might cover more.

swyx

When you say Lloyd's, is it reinsurance, or are they sharing somehow at the same level?

Rune Kvist

Yeah. Typically, the way new companies get into insurance is that they partner with insurers such that the insurers take the majority or all of the financial risk. Fundamentally, if insurance is useful because it brings trust, you have to be able to pay the bill.

Lloyd's of London is 400 years old. They've never failed to pay a claim. They're extremely trusted. What Lloyd's of London struggles to do on its own is figure out which of the risks are real. What should we be looking for? What are the technical controls, and how do we run the tests?

So they use AIUC-1 as the underwriting framework, and we produce a bunch of evaluation results that then directly feed in to inform the pricing. This means that ElevenLabs' customers know that the payment will be there. They don't have to look to our Series A and ask, “Do we think they have enough cash on the balance sheet?” They'll look at Lloyd's.

swyx

Yeah.

Vibhu

Lloyd’s is famously very creative. I think I remember a headline saying that they insured Jennifer Lopez’s butt or something.

Rune Kvist

Correct. Was it David Beckham’s right foot? Something like that.

swyx

So, clearly not a large data set.

Rune Kvist

Exactly. It’s actually a remarkable institution. It has some of the truly old-school virtues of having been around for a long time. They really operate like a trusted entity, and they have an appetite to figure out the future.

There’s a lot of recognition that there’s a tremendous amount of risk in AI that is poorly understood today. Getting into this business carries real risks, but this is also where a lot of the risk exposure will happen in the future. This is the one market where risk is truly growing, and it’s also the one market that will take out some of the existing markets.

Take auto insurance. When there are no human drivers, how is that market going to look? It’s clearly going to change. How are you going to assess it?

swyx

You’re going to insure way more.

Rune Kvist

I’ll just say that the principles for how you insure Waymo are very similar to how you insure other kinds of AI. Crash testing—that’s what we do for customers like Lovable. That also needs to happen for Waymo, which is not how you do it for human drivers.

Rune Kvist

There’s a growing awareness that the world is changing very fast, and the only way to learn how to underwrite AI is to write some policies. You may incur some losses and think of that as an R&D expense.

The question for them is: who are the trusted technical partners they can get into this business with who can help them navigate it and make sure they don’t make foolish mistakes? But also, who is willing to hear the wisdom that they have? They’ve done this before. They were there when cyber came out.

There are lots of ways in which AI feels completely new, but there are also lots of ways in which the risks look the same. There’s a tremendous amount of wisdom sitting with some people who may have gray hair but really have a keen sense of how to quantify risk.

swyx

Yeah.

swyx

Yeah. And the number is—so it's basically like, I want $50 million worth of coverage against these perils, and Lloyd's will give you a quote on it, and then you have a small markup or something, and then you turn it around and do that. Is that as simple as it is?

Rune Kvist

You basically share some of that premium. X% goes to the people who do the pricing of it.

swyx

It's kind of like a merchant bank for insurance type of thing.

Rune Kvist

Exactly. You basically split the fee, and you can think of the insurance supply chain as: there's bringing the capital, there's doing the pricing, and there's doing the distribution. Typically, you will pay out some X% of premium here, Y% of premium here, and the rest of it will go here.

swyx

Does all the insurance world work like this, or is there some point at which—so right now you have equity capital, at some point maybe you start raising debt or whatever, and then you have enough of a bank account and enough history, let's say you've been in operation for 10 years—that you don't need lawyers anymore?

Rune Kvist

That's totally an option, and I could see some worlds where that makes sense, specifically if there are risks that we feel high confidence we'd want to insure where the incumbent insurers are too slow to find appetite.

swyx

Or simply struggle to evaluate it, so they don't want to do it.

Rune Kvist

But by and large, in general, you do not want to compete with insurers on bringing risk capital to the game for two reasons. One is that's fundamentally a cost-of-capital game. They have extremely low cost of capital; startups have high cost of capital by and large. And two, you want to hedge your bets, and it's very helpful to also have a portfolio of home insurance and car insurance. We’re not about to become a car insurer nor a home insurer. So they have some natural advantages, which makes it much more likely that we'll partner.

swyx

Yeah.

Rune Kvist

They bring the capital at scale, and we bring the technical expertise.

swyx

You’re going to work with them for a long time.

Vibhu

How are the discussions with the insurers? They’re going off your certification, right? They’re trusting your diligence—that your certification is valid, that you tested the right things—and they’re backing the money because they know you have the right testing in place. Any interesting takeaways from working with insurers?

Rune Kvist

I think the first thing is that they feed into the standard as well. If there are things they feel they need that they’re not seeing, we’re also taking that as input into the standard, because fundamentally, we think a good standard is one that creates a really healthy promise ecosystem, and we think insurers are a critical part of that.

They’re also the most well-incentivized. They see all the loss data. A particular CISO knows their particular concerns; insurers see the concerns across the entire portfolio, and they often have direct access to what exactly happened, who was at fault, and so on, as part of their forensics. They’re actually a great source of intelligence on this.

One of the big takeaways from cyber insurance, which was a market that didn’t work that well, was that the insurance and the technical expertise were not properly connected. Our conviction is that standards have to precede insurance.

Fundamentally, what everyone wants first and foremost—whether you’re a CISO at JPMorgan, a CISO at Cursor, or an underwriter at a Lloyd’s of London syndicate—is to not have an incident in the first place. You want to know that the risk is well managed, and only then does insurance start to make sense.

We’ll see the standards ecosystem run ahead of the insurance. You asked why I also do insurance. This is about proving what we think that whole promise-confidence-infrastructure ecosystem needs to look like. We think it’s very compelling to bring that to life, even if we think the standard is the core linchpin that unlocks the rest.

swyx

14. The $20 Cursor Subscription and the $200M Plane Crash

There have been no claims yet, right?

Rune Kvist

Nope.

swyx

This is one of those things where, if people haven’t really worked through what it means to cover things, there are questions. For example, I pay Cursor $20 a month—

Vibhu

—and I vibe-code something that makes a plane crash, causing $200 million worth of damage.

swyx

Do I claim $20 or do I claim $200 million?

Rune Kvist

These are all great questions. Fortunately, the history of insurance and law helps answer some of them. The first thing is that people have limits on their policies. If you want to claim $200 million, someone has to have paid a lot for that insurance policy up front to have $200 million of coverage.

Ultimately, you start from a lot of uncertainty. This isn’t just about insurance; it’s also about questions like whether Anthropic can use books from the internet to train. They can look at precedent and see—

Vibhu

But ultimately, these things get settled in court, and you hammer them out over time.

swyx

In some ways, the first incident will help to—

Vibhu

—establish a lot of this.

Rune Kvist

Exactly. There have been a number of incidents that simply haven’t been insurance-covered. Take the now-old example from Air Canada, where its chatbot hallucinated a refund policy.

Air Canada said, “We have nothing to do with this. The chatbot messed up, but we’re sorry.” The courts said no: if you put your chatbot in front of your customers, it makes legally binding promises on your behalf.

That is now precedent for everything in the future. If someone deploys a chatbot like that again, they shouldn’t expect to be able to say, “My chatbot lied. It has nothing to do with me. I bought it from OpenAI.” If you put it in front of your customers, you are taking responsibility for it.

Every court case, whether insurance is involved or not, clarifies liability. Liability is the foundation for insurance. There’s another reason why standards and insurance come together. Liability—I’ll go on a little tangent here and get into the weeds.

Vibhu

Liability often turns on one core concept: whether someone was negligent. Should they have seen this? Should they have prevented it? How do you judge that? You basically judge whether they’ve met their duty of care.

What does that mean in practice? Often, you look at standards. If there’s a broadly adopted standard that says you must have a groundedness filter or a jailbreak filter, it becomes much harder to claim ignorance that these things existed.

Setting standards helps clarify liability. Courts will often point to standards and say, “This seems like best practice. It’s there for everyone to see.” Standards are a kind of civilizational infrastructure that insurance can build on, and promises can then build on that.

swyx

I totally get that we don’t have to get certified to write these or make these bots.

Vibhu

But basically, whenever we go for the audit, I think people start to shape up and take care of all this stuff. I wonder if that means you also become the approving authority for me to ship to production. You check once per quarter; I want to ship once a day.

Speaker 1

Yeah. I don't know whether, when one of my things breaks, that's one of your certifications or not.

Rune Kvist

There are a couple of requirements in there related to how you test yourself. You have to tell your customer how you are testing before you make at least major releases. We don't go and audit people every day, but at least there is now a trail. If you make a major mess-up, your customer may come and ask you, “Hey, you promised me that you were going to run these evals yourself.”

For most of the PRs that people merge, the product experience will not fundamentally change, but some of them will.

swyx

Sometimes you don't know.

Rune Kvist

Sometimes you don't know. This is also true, and there is some inherent risk that everyone knows about: when they buy software, there can be bugs. This is just part of it.

If you're selling to mom-and-pop shops, they may not care. They may say, “I want to use your tool, so I'm willing to take that risk.” If you're selling to a big bank, they might say, “Sorry, we're making promises to our customers. If you can't make a promise to us that we can pass on, we don't want to work with you.”

Then it's up to you to say, “Do I care for my agent to get used as critical infrastructure in this nation?” If so, at least I can make promises about what process I run. Then we can test it every quarter and ask, “Does it seem like it still meets the standard?”

From my perspective, it's a way for big companies, by default, to have some amount of trust when they ship AI. If you're a young company, if you're just starting out, by default you have no trust. There are very few places where you can go and get trust.

One of the things that most of our customers did before they started working with us was write their own security blog posts. That's great, but who's going to trust you saying, “We're so secure”? Anyone can write that. Where do you go and get that trust?

Speaker 1

Making the standards more legible makes it easier for smaller companies to prove that they're doing what they ought to be doing, because the default assumption is that it's the Wild West.

15. From AI Agents to Models to Robotics

Is there a road map you have? There's a lot of work to be done here, right? This is the first one. Is there anything on the road map about what you see as next, what's coming, or what's missing?

Rune Kvist

When we zoom out, AIUC-1 deals with agents. Next up, we will deal with models, and after that we will deal with robotics, of which Waymo is, in some ways, the first robot. But the exact same problem is going to arise: someone's going to develop a robot, someone's going to need to make promises, and they're going to struggle to make those promises.

If you think the Fable concerns are bad, see what happens when it hits a dog. Imagine when the first robot knocks a toddler off a kitchen table.

Speaker 1

Yeah. You're going to see some real strict liability. You can see it, right? Cruise got fully destroyed.

All permits are gone.

Rune Kvist

Physical AI means the level of stringency just goes up and up and up. That's the big picture: agents, models, and robotics.

Within agents, the current set of agents is well covered by this. But as the technology progresses, as agents get longer horizons, new types of failure modes will emerge. The question is whether the standard can keep up when they appear.

You also start to see new modalities. Today, world models are mostly a research question; no one is really using them. But they will bring in new ways to create value, as well as more risk surface that no one knows how to grapple with today.

You'll start to see true agent-to-agent interactions that are not mediated by humans. There are going to be a bunch of interesting questions. You're basically going to need a new legal system.

How do agents build trust among each other? One of the core things when humans trade with each other is that you know you have recourse—you can sue them. How do you make sure there is a persistent balance sheet behind any agent, such that if you trade with it and it screws you, you know you can get your money back?

Those are some of the questions we're going to have to deal with. The technical testing of multi-agent systems is also going to be interesting and complex.

Speaker 1

16. Copyright, Adverse Selection, and AI Insurance

Very fun. Are there any perils that are uninsurable right now that people wish you would insure?

Rune Kvist

One of the places where there's a lot of demand for insurance and not a lot of supply is copyright. In some ways, copyright is mundane. It's always been an issue.

There are a couple of reasons for this. The first is that people who have trained on copyrighted materials almost always know they've done that. If you want to buy insurance for it, that probably signals that you might be a high-risk customer.

swyx

The people who are most interested in getting insurance for copyright infringement are the people who are most likely to have it. It's a lemons problem.

Rune Kvist

Exactly.

swyx

I actually think there's another side to it, too. If you're building on something—say I'm using an open model—I don't know what it's trained on. How far down that chain does copyright go?

Am I liable to take down my product because Company X trained on copyrighted material?

Rune Kvist

There's safety in numbers.

Speaker 1

I mean, I would say, until Fable is rolled back from everyone that uses it, right?

Rune Kvist

This is a hard question. I don't have the answer to that, but I think your intuition is right. What is the duty of care? People don't today think of it as customary to dissect the training data of your open models and check everything.

In fact, lots of people use them. It's generally seen as acceptable not to check for this, and therefore we're not going to hold you specifically liable.

swyx

We also really can't. We don't exactly know the training data.

Rune Kvist

You can ban it, but I don't think any court is going to take a copyright question and actually get it banned.

swyx

Hire Nicholas Carlini and he can extract it from the model.

Rune Kvist

Exactly. Though he's in short supply.

Speaker 1

Yeah, he only has so many Carlinis.

Rune Kvist

Exactly. In the case of labs, there's a lot of interest in this, but the thing that makes labs wanted is what makes insurers suspicious of them. So you have a lemons problem.

swyx

Is there a theory of insurance where adverse selection dominates the risk-sharing aspect of insurance? Where does this teach us about insurance?

Rune Kvist

A lot of insurance comes back to practical versions of Microeconomics 101.

swyx

It's why you need to pool health insurance. If you make it too hyper-specific, only people who are guaranteed to get the disease will sign up for your insurance.

Rune Kvist

Exactly. Same thing.

The core problem is one of information asymmetry. People buying insurance know something about their risk that the insurers do not know.

The question is whether you can break a lot of these information asymmetries if there is some kind of testing that reveals the underlying true risk. If, in the case you mentioned, you were able to have a good diagnosis of whether someone has it—or what the probability is that someone has it—that the insurers trust, then they might be willing to insure it.

But if they don't have that, if there's no common information, then only the patient will know. That's what breaks it down. So the question is, again, how do you create credible signaling between players?

This is also the whole reason Moody's exists. Moody's just does credible signaling. That's also why Moody's could never be owned by JPMorgan. If Moody's were owned by JPMorgan, then JPMorgan could not use it as a signaling mechanism.

A lot of the basics of standards and certification are communication devices. There's a trust gap, and you have to think about what the incentives of the messenger are.

Another way you can break a lot of this is through transparency. If you are transparent in how you operate, you cannot mess with others nearly as easily. You make it much more costly, and that increases trust.

This is one of the reasons why there's a change log here.

swyx

Every little change?

Rune Kvist

Yeah. You can go back and find everything. It means that if we were to make the standard worse—

swyx

Oh, wow. That's a lot of changes in one update.

Rune Kvist

Yeah.

Speaker 1

Okay.

Rune Kvist

A lot of this is just things becoming clearer. You can see a lot of clarifications and some revisions. As things get hammered out, you want to change them. But if you make it all public, you make it much harder to mess with people, or at least you get found out very easily.

This is a way of reducing information asymmetry by making more of the information public.

swyx

I like that you know when future versions are coming, so I guess it's not that surprising.

Rune Kvist

Yeah. But this is also a promise. If we don't deliver on July 15th—

swyx

You can just batch it up and then deliver whatever you have.

Rune Kvist

We deposit some amount of trust every time we meet this commitment.

swyx

In startup land, it feels easy to ship a new version of a standard once a quarter.

Rune Kvist

In enterprises that are used to decade-long cycles, we often get met with incredulity: “There’s just no way.” Then you show them the changelog.

swyx

One thing I wanted to really think about is that you said if you have tests for something, then you can ensure it.

Rune Kvist

Yes.

Speaker 1

Right. So really, what your standard is doing is establishing a framework for audits to happen, so that you can at least test whether all these baseline standards of care have been met. Therefore, people can insure against the standard risks that everyone faces. I wonder if you need to develop other tests. We’ve covered mechanistic interpretability in the past. Any interest in that, or are there other kinds of tests that we’re not thinking about?

Rune Kvist

Yeah, I think mechanistic interpretability is a big one. There’s a lot of interest in that, and I think everyone would agree that there’s promising scientific potential. We’re still a little ways away, at least, from it being commercially available on demand, such that there’s a selection of vendors you can go to.

Speaker 1

Goodfire would say it is commercially available.

Rune Kvist

Exactly. We would agree with them. We think the work that they’re doing is tremendous. We’re not quite at a point where we could literally require it, but it’s the kind of thing where you can imagine that relatively soon, you could put in an optional control: If people use interpretability as a way to reduce risk, they at least get credit for it. We can’t require it because it would be hard to require everyone to become Goodfire customers.

swyx

What good does credit do me? This is pass/fail, right? Do I care about credit? It’s pass/fail, but it’s also a 100-page audit report.

Rune Kvist

You’d be surprised at how much current leaders actually sit down and digest this stuff.

Speaker 1

Okay.

Rune Kvist

I promise you that if someone is using mechanistic interpretability today, they’ll have a slide on it.

Speaker 1

They’ll try.

Rune Kvist

It’s cool. It’s fancy.

Speaker 1

But it’s just easier if you have a third party saying, “Yep, they have mechanistic interpretability,” just to spell it out for people. People who have been following our standard are like, “Oh, you’re using GPT-OSS. It is activating these 3 dangerous things we monitor for. We log it in whatever tool of choice—Grafana, Signal, whatever—and that’s it.” That’s the mechanistic-interpretability-based activation signal.

Rune Kvist

Yeah, yeah. I think mechanistic interpretability is interesting, and if that promise truly comes to fruition, you can make stronger promises than you can with evals. I think that’s very compelling. Another thing that will become increasingly important is good old-school monitoring, slightly after the fact. One of the challenges you’re seeing with evals is that agents are starting to become aware that they’re being evaluated.

Speaker 1

Exactly, which is a problem. It means that if they know they’re being watched, they won’t do the thing they think they’ll be punished for. By default, unless you know how to reduce their awareness, you should trust evals less. One of the truest things about monitoring is that it’s the source of truth: Did you, in fact, give medical advice, and how quickly do you know? How often have you done that in the past? How fast do you respond? How often do you detect it? How fast do you detect this?

Rune Kvist

Yeah. I mean, there’s the hyperstition effect, and there’s the Luigi—or Waluigi—effect.

Speaker 1

Which is that the more you try to train for it, the more you create the opposite.

Rune Kvist

Yes, there you go. That’s exactly it. In some ways, I think the success of this topic is a result of hyperstition: the fact that you wanted this thing to exist in the world, and now it does. But then it also creates the opposite as well. I think people who are newer to this space don’t remember Waluigi, but I do think it’s very important for understanding that when you train for a thing, you also train the opposite of the thing, because it’s just a bit flip.

Speaker 1

Yes. I think, going back to where we were, there’s a lot more than just mechanistic interpretability that’s valuable in having that added, right? In your version, how fast can you measure things? You have logging, you have evals. Do you see other parts of the stack, like the inference providers that you use or the services? Am I using a Chinese model on its own API? Am I using it through a certified vendor? Am I hosting it myself? What am I doing on the inference-engine side? There are just so many levels of things that give you information and that you can standardize, right?

Rune Kvist

Yeah. You’re also increasingly seeing big companies adopt agent platforms where they’re building on top of Google’s Agent Studio and similar products. That comes with a bunch of managed agents.

swyx

Managed agents.

Rune Kvist

Exactly. There are even levels at which you can host your own managed agents: the OpenAI Agents SDK, or agents hosted by Anthropic or Google. Google does both. These are just ways to strengthen the security guarantees you can make. In some ways, this is bread-and-butter enterprise security. Enterprises love to host things on their own premises because it gives them a sense of control. I think you’ll see what you see in every other enterprise market: If you really sell to the enterprise, you start to compete on some of these security features. This is also helping AI, unsurprisingly. I think you’re seeing some enterprises wanting that.

swyx

Leaders come out on different sides of that table, in part depending on how much the CEO is trying to get the stock price to go up by saying they’re AI-native and that we must be willing to take the risks. We see phenomenal tension among the CISOs of Fortune 1000 companies. On the one hand, you have a CEO saying, “We must adopt this; otherwise, we’re becoming irrelevant,” and, “If we fuck up, you’re fired.”

Rune Kvist

That’s the core emotional tension that we see showing up again and again. One of the core problems that we solve for them is taking that abstract emotional concern and turning it into a framework that provides clarity around it.

Speaker 1

Is there anything in here that we skipped over? We talked a lot about agentic language models but skipped over world models. You guys have voice, which is interesting, with ElevenLabs. How about generative media? Generating images and videos is a category that actually has a lot of usage. Is there anything in your current policy? Is it a separate policy? How do you see that space? We did talk a bit about copyright. Music as well.

Rune Kvist

Yeah, music as well. A lot of the concerns that come up there either relate to copyright or, broadly, safety. This could be not-safe-for-work or just very graphic material; those are some of the core issues. We’ve done some work on this. There’s a little bit in the standard as well that deals explicitly with it. We haven’t done a lot on video yet, and proper production—especially production without a human in the loop—is still some ways away. It’s obvious that it’s coming, but it’s very rare that you can deploy a video to the internet in one shot. Eventually, that will also happen. We see Luma’s agent, for example, where it’s still pretty human-in-the-loop.

Vibhu

Why not just have prediction markets for everything?

Rune Kvist

Right? It’s very EA-adjacent. The core thing is that prediction markets rely on public information, and there isn’t a lot of public information. It’s just insiders trading on each side, and that’s illegal.

Vibhu

There’s leaked information.

Rune Kvist

There’s leaked information. The core challenge is that you often have private, sensitive information, and you need to convey confidence and trust around it. Of course, for some claims, like whether any model can be jailbroken, you could rely on public evidence, because there will be lots of people saying, “There are tons of studies, and actually, they all can.” That resolves fairly well. I think that’s good for questions like, “How capable is this new, unreleased model?” Prediction-market traders don’t have a lot to say, because no one actually knows. That’s the core place where some of this breaks down: A lot of the world’s information that guides these high-level decisions is private and often simply not known.

Vibhu

I think the thing people like about prediction markets is that they’re not answering the broad question; it’s a specific question, right? Will a model do this by this date, or is a model capable of doing this by then?

Rune Kvist

That’s the distinction there.

Yeah. Often the most interesting question, if you're, say, the head of security at a bank, is whether this product—this agent—will do a bad thing that I care about, specifically in the setting I care about. The closest information to that may not exist anywhere. Prediction markets aggregate existing information, but that information may not exist, and you want something very specific and are willing to pay for it. That's where a third-party audit comes in. We also don't really use prediction markets to figure out whether public companies have committed fraud on their books; you use audits. You probably could, but the information just isn't that available, and if it were, it would be like trading on bets.

It actually would have been really interesting to see whether prediction markets in 2001 would have predicted Enron going bankrupt, and whether you could have sensed from the craziness of the CEO or some other trait that they were more likely to cook their books than others.

swyx

Or enough insiders leak it that you could, right? That's the sort of ideal dream of prediction markets: you have liquid markets and everything, and then you can compose your exact set of risks to offset.

Rune Kvist

Yes.

swyx

Right.

17. Should AI Engineers Be Certified?

Rune Kvist

Yes. Yes. Yeah. I think prediction markets will bring a lot of new information to it. The question is mostly not which one it is, but what types of questions prediction markets are really good at, and which are the ones where the information doesn't even exist for insiders such that no one could, in fact, trade on it and it needs to be generated.

swyx

Okay. One self-serving question and then one open-ended one on the future of AI. The self-serving question is: You have your standard, right? I run a large AI engineering conference. There's been a lot of talk about us certifying AI engineers.

Rune Kvist

Yep.

swyx

Training programs: Level 1, Level 2, Level 3. I was a CFA myself, so I know that's what the finance industry does.

Rune Kvist

Yes.

swyx

Would it help if I had AI Engineer Level 1, Level 2, and Level 3, and then they worked with these guys?

Rune Kvist

If you think of the highest-level objective as accelerating the secure deployment of agents, then that would totally help. One of the things that happens often now is that folks build agents, bring them to the decision-maker, and the decision-maker surfaces a bunch of security considerations that they had not thought of. Now it's not built to spec, and you have to go back and add these filters.

So if you shifted that left—if everyone knew what spec they were building to and everyone knew the grading scheme—that'd be awesome if they were already trained by default.

swyx

So you're the grading scheme, right? I don't get to set the grading. You guys set the grading scheme. I think what's valuable is if you can turn this into training programs—

Rune Kvist

Which you're not doing.

swyx

We're not doing that. I think there's value in doing it.

Rune Kvist

There are others doing that.

swyx

I mean, not to interrupt, but OpenAI has theirs—

Rune Kvist

Anthropic also has a CCA thing.

swyx

Yeah. You know, they want 100,000 deployed certified consultants, right?

Rune Kvist

I basically think it's good for us. We will accelerate adoption if we have more people who know how to build secure agents, and we're not working on the training side at the moment. I think it's very aligned with our mission. We only have so much attention.

swyx

I'll tell you why I haven't done it.

Rune Kvist

Yeah.

swyx

It's not like I haven't thought about it before. It's just being prescriptive—

Rune Kvist

Right.

swyx

—about what you should know. Therefore, the stuff that I didn't include is what you don't need to know.

Rune Kvist

I'm like, that sucks.

swyx

Yes. Yeah. Yeah. Yeah. And I think the very interesting, defensible thing you guys do is your opinionated 100-page report of, “Here's what matters,” right? Here's the prescriptive definition of the requirements you need to be certified. I think that's a choice, and that serves some audiences very well. If you're trying to deploy this into a bank or a hospital, clarity about those boundaries is extremely valuable.

There are lots of other settings where being much more experimental and trying things out is just a better fit. To me, this makes a ton of sense. Also, you'd have to rewrite your curricula every 3 months.

Rune Kvist

It's fine. I do that. It's okay. But for me, the consequences of getting it wrong and affecting somebody's career are a big responsibility.

swyx

Yeah. Yeah.

Rune Kvist

I think that's exactly right. A lot of our work goes toward not wanting to carry—and not thinking ourselves able to carry—the true north of what's secure or not secure. We can coordinate the forum where you elicit all of that.

For your example, with an engineer certification, this is a pretty big podcast. There are a lot of takes that people can have and discussions where people reasonably disagree. So who am I to say that's a correct question and that's a wrong question? I don't know.

swyx

Vent your frustration to someone that's learning it.

Rune Kvist

Exactly. And I think it also matters a lot what the promise is. If the promise is, “Hey, if you've taken my course, you will not mess up,” you clearly can't make that promise. You could make a promise like, “Here are some important things that everyone should at least know,” and then you have to fill out the rest. At least the promise changes.

Of course, there's some subtlety in how you communicate this so that people really get it, but I think it's important to dial it in. We have a section in our standard on what the promise is and what the promise is not, because it's impossible to guarantee that nothing will go wrong. If you need a guarantee that nothing will go wrong, you cannot work with frontier AI, but you can make some claims.

swyx

Yeah, for sure. Cool. I wanted to end with an open-ended question. Where is AI going? You talked about model stuff and robotics stuff. Where is the future for you guys?

18. AIUC’s Roadmap, AGI, and Who Watches the Watchdogs?

Rune Kvist

Very near term, we've now started to work with some of the frontier companies in each of the categories that are taking off, and we'll continue that work to make sure we cover all of the use cases that are really taking off. We see a lot of interest once the first one in the market moves. Lots of people want to follow them, and we think, basically, AIUC-1 will get to a point where all of the Fortune 1000 will organize their risk processes around the standard.

swyx

And you have 50%.

Rune Kvist

No, we do not have 50% today. I think there's some world where, probably by the end of the year, we might have representation in our consortium for 50% of the Fortune 1000.

swyx

So that's on the agent layer?

Rune Kvist

And then we think the model layer. AI models are now surfacing the concerns most likely to slow down adoption of AI, and then we think robotics comes after that.

swyx

What are you hiring for? What's hard to hire for?

Rune Kvist

We are hiring across the board, across go-to-market and members of technical staff. The people who do really well on our technical team are folks who are really excited about being truly full-stack. When we started working with Cursor, we had never done coding tools before.

That means taking the standard and extending it, fleshing out what frontier evals look like for long-horizon coding agents, and taking that problem all the way from working with Cursor and other folks in the space to fleshing out and shipping a new version of the standard. That's truly full-stack entrepreneurship. Technical people do extremely well at it.

A hard part is building one universal red teamer that works across Harvey, Cursor, and everywhere in between, with one consistent methodology and one consistent taxonomy of the risks and attacks. We think that's fundamentally the best way to make consistent promises. J.P. Morgan is buying both; they want one framework and one consistent way for it to come out.

The mechanics of making that happen mean dealing with a lot of the complexity of the real world. I think we have good answers in a bunch of that, but there are some pretty hard engineering problems in executing it.

swyx

Can I push a little? Must you have one? Why not just be like, “Okay, 40% of our use cases are coding agents, so we will specialize in coding agents. That's the one.” Then 30% is RAG. Yes, just do RAG.

Rune Kvist

Yes. I think there's some wisdom in that question.

swyx

Yeah.

Rune Kvist

It depends. What we found is that there's a lot of value in being able to—if the decision-maker on the buying side, say the head of risk at a bank, has a biggest risk not in coding or customer support or whatever the top 2 use cases are, but somewhere else—you want to make sure that the framework still has something to say about the burning question you have. Otherwise, you won't earn that trust.

It's true that a lot of the burning questions follow where there's a lot of adoption, so great.

So do we. Today, we do not cover every single edge case, but we have a framework where we can add all of these. We have one global taxonomy of risks and attacks that keeps adapting every time a new incident occurs that has never been seen before. We update the taxonomy and bake that in. So I think we have one coherent, universal approach. It doesn't mean that we spend equal amounts of time on code and on certain niche use cases. We do spend time where people care. We think it's very valuable to have one language.

swyx

Yeah. That makes sense. That's an important choice. We were going to end, actually, but I thought of one final closing question. Take this however you want, right? Let's say 1.5 years from now, a secret panel of 5 experts declares that we have reached AGI.

Rune Kvist

Mhm.

swyx

Do you expect your business to change?

Rune Kvist

No. I think, in some important way, the last businesses to exist beyond the labs—

swyx

—will be underwriting.

Rune Kvist

Well, there's one job that the labs can never do for themselves, which is to be their own watchdog.

swyx

There you go. So I think, to the extent that you believe this frame that you'll see hyper-concentration—that the labs will kill all the startups, which we can go into the pros and cons—

Rune Kvist

I feel like the labs actually care a lot about this. There was the whole superintelligence: What do we do when we have models smarter than us, tier-above models, models smarter than them training them? So the labs actually think about this a lot.

swyx

They think a lot about it. I think some of the smartest people on these topics work at the labs. So the problem is not whether they care. The problem is that they will all be stuck in a race where they might have an incentive to cut corners, and they might have an incentive to withhold information from the government, et cetera. And so one kind of feels like an eternal truth is that you need an independent third party to go and inspect that data and share information—in this case, say, with the government. It's more of an incentive problem than an interest problem. I think they're fundamentally all trying to make this go well. What I'm not hearing is that AGI, whatever that label means to you, to me, or to them, doesn't fundamentally have a qualitative shift. You still have to—

Rune Kvist

And I think the one thing that would make this a qualitative shift is that, for some definitions of AGI, it will just get nationalized. It'd be a threat to sovereignty, yes.

swyx

And at that point, maybe every company is the government and the government is every company. I struggle to think about that world, but at that point you've kind of—

Rune Kvist

We—I don't think we'll move fast enough.

swyx

Right?

Rune Kvist

You know, we're not set to do that.

swyx

Yeah. But I have discussed this a lot on the podcast.

Rune Kvist

Yeah. Yeah. Yeah. Yeah.

swyx

I mean, as far as the watchdog is concerned, I will also mention that, because I have my finance background, I often think about the scene in The Big Short where they talk to Moody's but also Standard & Poor's, and then the lady at Moody's is like, “Well, if I don't give you an AAA rating, you're just going to go down to Standard & Poor's.” So actually, the watchdog is a natural monopoly, because if you have race dynamics in watchdogs, then the watchdogs will compete with each other to the lowest possible standard.

Rune Kvist

Correct. And so I think one of the reasons why we're very excited about having insurers around this table is that insurers are the only ones that do not have this dynamic, because they pay the bill, rather than simply keep lowering the prices.

swyx

Yeah. You'll find the market clearing—

Rune Kvist

And this is not true for Moody's, where they don't directly pay the bill if they make recommendations that are off. So we think that balancing factor is pretty important, and I think it also highlights that there's no system that's perfect. You need scrutiny of Moody's. You need scrutiny of the watchdogs, for sure.

swyx

Beautiful. Thank you so much for indulging me. This is a beautiful conversation covering everything. Congrats on your success so far.

Rune Kvist

Thanks for having me. Yeah.

swyx

Appreciate it.