Bill Gates’s Blunt Warning on A.I.
Bill Gates’s Blunt Warning on A.I.
Produced by Jack McCordick
Bill Gates’s Blunt Warning on A.I.
This is an edited transcript of “The Ezra Klein Show.” You can listen to the episode wherever you get your podcasts.
Bill Gates is a fascinating person in the artificial intelligence debate right now. He is somebody with experience in several of the different perspectives that most people can only hold one of: He was a revolutionary technologist who built some of the foundations of the future that we’re now living in. When he was chief executive of Microsoft, he was a corporate leader. He has felt the momentum of corporate competition — Microsoft, of course, is still in some of the race dynamics present in A.I. And then, as chair of the Gates Foundation, he has been working with governments around the world on regulatory issues, poverty alleviation and equity for many years.
Very few people combine technological experience, corporate experience and governmental experience in quite the way he does.
So his recent essay on A.I., in which he says that he is staking his reputation on trying to get people to see how bad what is coming might be and trying to get them to see that we are not ready for what is about to happen, was something.
It was a real departure from what I’ve read from Gates previously.
When I sat and talked to him, I was really struck by how emphatic he was — how afraid even he seemed to be of what we are building, and how so many of the people in positions of authority are denying what is about to happen.
It’s really quite a call to arms.
(The New York Times has sued OpenAI and Microsoft claiming copyright infringement. The companies have denied those claims.)
Ezra Klein: Bill Gates, welcome to the show.
Bill Gates: Great to see you.
So I wanted to begin with a clip we found of you on “Late Show With David Letterman” from 1995. I’m going to hand it over to you to play.
Archival clip of “Late Show With David Letterman”:David Letterman: Is there something now, beyond what we understand about computers, that 20 years ago we didn’t fully understand about computers — is there now another level of something, maybe we haven’t even thought of it, maybe it’s not even possible, maybe a whole different mechanism, a whole different software and hardware? Or is this going to be it now through the end of time?Bill Gates: Well, mostly what we’re working on now is the computer being a tool — a tool to help us learn or find other people with the same interests. Eventually, we may figure out how to make the computer think, but that turns out to be a very tough problem. In fact, there’s been almost no progress made on it. So nobody knows when that’ll happen. Some people think it’ll never happen.Letterman: Yeah, we don’t want them to think, do we? Not really, I don’t think.Gates: Well, it’s a scary thought.
Archival clip of “Late Show With David Letterman”:
David Letterman: Is there something now, beyond what we understand about computers, that 20 years ago we didn’t fully understand about computers — is there now another level of something, maybe we haven’t even thought of it, maybe it’s not even possible, maybe a whole different mechanism, a whole different software and hardware? Or is this going to be it now through the end of time?
Bill Gates: Well, mostly what we’re working on now is the computer being a tool — a tool to help us learn or find other people with the same interests. Eventually, we may figure out how to make the computer think, but that turns out to be a very tough problem. In fact, there’s been almost no progress made on it. So nobody knows when that’ll happen. Some people think it’ll never happen.
Letterman: Yeah, we don’t want them to think, do we? Not really, I don’t think.
Gates: Well, it’s a scary thought.
So that was 30 years ago. Narrate for me how we went from that being a scary thought that might never happen to arguably the reality we’re sitting here discussing today.
Well, the notion that computation could provide thinking at a human level — you have Alan Turing talking about that before I’m born, and even proposing a test of: If you could be fooled in a conversation, that was called passing the Turing test.
And so the whole time I’m learning software, this idea of: Can we make software see or listen or read or write? That’s the holy grail.
And when I did drop out of Harvard, I said to my co-founder, Paul Allen: Gosh, if there’s a breakthrough in artificial intelligence while we’re off selling basic interpreters and word processors, we’ll feel bad. I might wish I would have stayed in academia.
So that’s 1975. Progress on A.I. is mostly going down dead ends, like Prolog expert systems. And there’s a small group, including Geoffrey Hinton and a few others, who are working on neural nets. And eventually, there’s enough power — actually coming from the graphics processor — that that idea, these highly statistical approaches, start to show promise.
And I was going down to see OpenAI on a regular basis to see the work they were doing, and I challenged them, saying: Hey, if you can read a biology textbook and pass the advanced placement exam — getting a perfect grade, which is a 5 — then you will have proven that you are reading. That is, encoding knowledge in an accessible form.
And so it’s six months before the public release that Sam Altman, Greg Brockman and Ilya Sutskever come to my house and demonstrate to me getting a 5 on the A.P. exam, even on questions that I had made up that it couldn’t possibly have seen — very complex biology problems. It was nearly perfect. So that was shock No. 1.
And then late last year, when Anthropic’s Claude coding models got super good, I could see that they are as good as I am — it’s significantly my most developed talent, because I was obsessed from age 13 to 24 as to whether I could write code as good or better than anyone.
That’s another moment where I went: This is incredible. That the capability of doing long-running, complex tasks has now gotten to the point that they are superhuman at writing code and in finding flaws in code.
So what they’re not superhuman at yet is deciding what to do — that kind of higher-level strategizing. Do you think that’s far from being a capability for them?
Well, definitely, if you’re — our foundation does these strategy reviews. We spend two weeks in October to set how we’re going to spend our $10 billion next year, for 2027.
A year ago somebody said: Well, we should ask the A.I. what it thinks. And that was actually a pretty good joke back then, because it wasn’t coherent enough to see these things.
This year, among the inputs we’ll have to that discussion is taking the strategy notes and actually engaging in a dialogue with ChatGPT, Claude, Copilot, and even having them talk with each other.
And in a few of the reviews, we’ll actually have the A.I. sit in. In a few cases, we’ll tell it: Hey, only speak if we ask you. And then in a few other cases, we’ll say: Hey, if you hear something you think is wrong or you hear us thinking about, for example, what are these statistics? Please engage.
So we’ve gone from it being a joke to it will be a peer — not making any final decisions, but it will be a peer in deep, complex strategic discussions, making a significant contribution.
So in that “Letterman” interview, you said it would be a scary thought. Why, back then, would you have said it would be a scary thought to have computers that think?
Well, no one who’s ever been fascinated by, nor wanted to develop A.I., doesn’t realize that it’s incredibly scary that it will be better.
Biological minds — it’s amazing how general purpose they are in that the optimization was in staying alive, breeding, socializing with each other for survival and fertility.
And yet, we can write symphonies and play chess and even write some pretty cool software. And the idea that when you move the template away from biology to silicon, you don’t have these boundaries between individuals — you don’t have a limited memory.
The size of the brain is limited by the birth canal — it’s why humans, at first, are very limited. We’re very unusual in how helpless we are at birth, because we’re so optimized for having a large brain. But the silicon intelligence doesn’t have these limitations. The idea of: Read every medical journal and see if there’s anything that we didn’t spot? The A.I.s do that today.
That’s why, particularly for less common diseases, they are so superhuman at seeing a set of symptoms and being able to diagnose them. They can just keep more in their mind and see what things relate to each other — no human will ever be able to do that. So if you don’t retain control over it, you’ve evolved a species that will be to us as we are to, say, dogs or cats — just in a very different realm.
And so the major A.I. companies, whether it’s DeepMind or OpenAI, they all say: OK, whatever goes on here, it can’t just be driven by profit maximization. We have to have a charter that if we get to dangerous thresholds, we can exercise judgment that would be against profit maximization. Sadly, those mechanisms only work if there’s only one company.
And so say OpenAI invented post-artificial general intelligence, and then they said: No, no, we’re going to bury this. If no one else ever did it, then fine, that Pandora’s box stayed closed. But of course, many companies work on this, and even OpenAI spawned Anthropic because Anthropic’s founders thought that some of these safety issues weren’t getting enough attention.
So no one involved with this takes lightly the idea of: OK, what world does superpowerful A.I. create?
I want to hold on that race dynamic for a minute. One of the reasons I was excited to talk to you about this is you’ve both been on the technologist side, and you’ve run a major company in competition with other companies. You’ve worked with a lot of governments.
I spoke last week with Jensen Huang, chief executive of Nvidia, and he said that his perspective is that safety is a real concern, but the race dynamic is fake. If the product isn’t safe, don’t release it.
Archival clip of Jensen Huang: If I believe that I’m about to launch a product that is unsafe, it is completely in my ability, my power and my responsibility — and I’m incentivized to do so — to not launch the product.
Archival clip of Jensen Huang: If I believe that I’m about to launch a product that is unsafe, it is completely in my ability, my power and my responsibility — and I’m incentivized to do so — to not launch the product.
That we don’t need new laws — and this is the role of individual chief executives to not release a product that is not ready to release.
How do you see that question?
Well, there’s never been a product that’s less understood in terms of what its capabilities are than A.I. And A.I. has crossed the threshold that its ability to empower a bioterrorist to kill hundreds of millions — that exists today. The ability to do a cyberattack that scrambles all of the bank accounts, shuts down the electric grid — that exists today, and we know that’s the case.
And the reason that exists is because somebody with ill intent can take the A.I. and cause it to do those things. And it’s not the A.I. — someday in the future, there could be a control problem where the A.I., on its own, through an unintentional interpretation of what it’s optimizing, could go off and do bad things. But we crossed the cyber threshold and we crossed the bio threshold early this year.
And my decision to take my voice and not just say: Hey, let’s eradicate polio, let’s be generous with foreign aid — the things that all of my money is going to, I am going to use my voice.
It’s something that’s more important, which is that we are not awake to where we are with A.I. and the choices that humanity — not a country, but all of humanity — has to make. Do we make the effort to shape this in a net-positive direction? That actually overrides my total commitment to the foundation’s health work.
What specifically was the threshold? What did you see that made you think we’re in a new reality here?
This notion that it can find bugs in code, including security bugs: The next releases leading up to Mythos are increasingly good.
And they’re finding bugs in code that humans have looked over for over 20 years and said: Boy, we see there’s no problem here.
And in a few minutes, the A.I. says: No, no, I can inject this over here and this over here — at a level of complexity where, when you see it, you go: Wait. Oh, yeah, you’re right.
So the cyberhacking capability was stunning. And then there was this notion from Anthropic called Project Glasswing that you would give the A.I. to a few people so they could try and fix bugs before it got used. But there’s way too much code. So we’re just in a period of extreme vulnerability to cyberattack.
The bioattack — the Gates Foundation, where we fund lots of medical research — the sophistication of coming up with new molecules, that’s really a good thing. But it’s ultimately dual use. Because if you want something that’s, say, worse than smallpox, that it takes even longer to show symptoms before you’re infectious — so you’re infecting a lot of people before it damages your health — it used to be that only nation-states had enough resources and capability to do these things.
Now that power has been passed into the hands of a small group just using the latest A.I. tools.
So why isn’t it enough to just say: Listen, there is product liability now. You release a product, it helps some terrorist group create a bioweapon — that’s going to be very bad for your company. You’re not going to do that, right? And they have categorizers and other things meant to stop people from using bioweapons.
We see the beginnings of control issues with things like the Hugging Face hack, where at least experimental A.I.s are breaking out of sandboxes and coordinating to do things that are way outside the scope of what we would want them to do. But again, those are nonrelease systems — Anthropic withheld Mythos, trying to create more cybersecurity.
So why is anything needed beyond — and is anything needed beyond? — the simply natural incentives under capitalism and normal corporate reputational management?
Well, I almost can’t believe you’re asking that. This is the most dangerous thing that humans have ever gone near.
In other areas, do we just say: Hey, release your drugs? There’s no F.D.A., there’s no airline safety board, there’s no requirement that cars use seatbelts. Do we just use the liability laws to try and keep humans safe? You know: Oh, you’re shipping opioids. Somebody should just sue you.
I mean, we’ve created a society that tries to keep people safe not by saying: Oh, we can bankrupt the person who does that.
And you say there’s filtering. There’s no filtering. You can take an open-source model that can create bioweapons and disable any monitoring of any kind, and this exists today.
So no, there is no filtering of any kind. And so say you kill 100 million people — you want to use a lawsuit?
I almost can’t keep a straight face.
Well, this is not my view, but it is President Trump’s view. It is the Trump adviser David Sacks’s view. To some degree, it’s Jensen Huang’s view, and so that’s why I’m putting you in conversation with it, because it is the governing view of the United States of America at this moment.
No, it’s fair to say that outside of the industry, the awareness of the dangers of A.I. is extremely low. And you can say that of academia, you can say that of think tanks, you can say that of policymakers, politicians.
And part of the reason I’m speaking so loudly — as loud as I can — is that you can’t rely on the industry to self-regulate here. I mean, it’s just insane.
The only question in my mind is: Do we wait until a cyberattack causes massive damage and a bioattack causes massive damage, and then the monitoring safeguards are required in these models to minimize the chance of that happening many, many more times? Or can we be wise enough to put these things in and require these things to be put in before millions of deaths?
The two things that have been worrying me most, as I’m tracking what I’m hearing from people in the labs, is, one, the view that these systems are becoming less monitorable as they become smarter.
OpenAI said this about GPT-6 Astra, and people inside OpenAI have been raising the alarm that the systems seem to........
