Discussion about this post

User's avatar
Felix Choussat's avatar

This is good stuff. General thoughts on each of the premises:

Chinese fear of disempowerment:

I feel much more confident (say, 90%) that China will be worried enough about US AI to sabotage it for two reasons:

- First, I think the “missing mood” of the Chinese government will quickly erode once we have AIs with strategically relevant capabilities (ie bio uplift or autonomous hacking), since these capabilities present asymmetric threats to the government even before RSI becomes possible. The CCP has strong incentives to take these empirical capabilities seriously (to limit proliferation risk though deployment restrictions, or implement them as part of their own military operations) and will receive painful reminders if it doesn’t (such as suffering criminal or state-sponsored cyberattacks). From there, the attention on AI as a national security risk/asset will probably expand to include future, more powerful AI systems.

- Second, you don’t need to believe a DSA is possible in order to want to MAIM. China’s ingrained instinct to maintain strategic parity is probably enough to push it to try to weaken/steal from US AI projects, although it might not be willing to escalate to the higher tiers of MAIM without the fear of suddenly losing its sovereignty.

As a counterpoint, governments can sometimes remain amazingly strategically unaware when local political incentives support that. The Soviet bioweapons program, for example, only became a strategic priority in the late 70s: years after both signing the BWC and the US shutting down its own bioweapons program in 1969. The reason for this is that Soviet scientists had developed a socialist theory of genetics back in the mid-twenties, the flaws in which made developing effective bioweapons impossible. Regardless, the theory was rubber-stamped by Stalin and became political law in the years afterwards, even after the shape of DNA was modeled in the 50s by the US.

- [Counter to the counterpoint] On the other hand, the Soviet Union never had to face non-state bioweapon risks, and their primary opponent willingly gave up their program. There was no forcing function to make them notice this shortcoming.

^ For more about this ridiculous story you can check out Ken Alibek’s Biohazard or look up the history of Lysenkoism.

China will MAIM:

My general view on this point is that the Chinese government will very likely pursue lower tier escalation strategies (95%?) but would be reluctant to up the ante to direct strikes, especially those that include massive collateral a la nuclear HEMP (20%? It could become internally normalized by an attack on Taiwan to disrupt the US supply chain, or an attack on US interests that's not on US soil like blowing up ASML). Cyberops are the likeliest candidate of all, since they’re both extensions of current policy and needed to facilitate even fast following strategies like model theft.

Assorted reasons why I think extreme escalation is unlikely:

- It’s hard to know how urgent escalation is at any given moment, because even the target can’t know how far away they are from RSI, or how quickly takeoff will bring them to superintelligence. This makes preemptive escalation very hard to justify, since you might need to do it before you see empirical evidence of harm. This applies doubly to fast takeoffs and misaligned AIs, where either the window of vulnerability during which RSI is apparent could be very small or where the AI itself waits to reveal its misaligned interests until it’s confident that it has a decisive strategic advantage.

* [Sidenote on the variability of DSAs]: a misaligned AI would need a much smaller decisive advantage in order to be willing to take drastic action than a human state would. The reason for this is that the AI’s values are inherently more defensible: unlike humans, most of what it cares about is likely to be in the long-term future, so it’s willing to trade aggressively as long as it can rebuild from the ashes. A human country, on the other hand, is forced to care about both eventual victory and its civilian population, which means that it needs to be able to overcome countervalue attacks in order to get a DSA. For example, the US would need to overcome nuclear deterrence to safely disempower China, while a misaligned AI likely wouldn't mind one of its datacenters getting nuked in retaliation as long as it can eke out a win.

- Norms over great power conflict have huge inertia. Although the US could have taken Von Neumann’s advice to nuke Moscow preemptively to reduce the chance of a future nuclear war (which, considering how close we came with Arkhipov, Cuba, and Petrov might have been sound logic), the idea was too far outside the Overton window to consider. It will very likely be emotionally unpalatable to condone unilateral strikes to prevent the rise of an ASI power, *even if* policymakers understood the abstract potential of superintelligence.

The US will back down:

This is the one I feel the most uncertain about, but I’m relatively confident that the US would not severely escalate in response to MAIM for the same reasons listed above. Most of my uncertainty is around whether MAIM would significantly slow down the U.S, especially if China is unwilling to escalate to the most extreme options. In light of those weaknesses, 70% feels reasonable.

- A major reason I don’t expect much escalation from the US over sabotage is that MAIM itself can act as a controlled outlet for retaliation. Hawkish arguments for escalation to broader hostilities won’t have to just beat out the doves, but also people who advocate for the simpler approach of continuing or intensifying existing cyberops. Why risk blowback from the international community when you can far more discreetly follow the path of least resistance?

- On the other hand, MAIM might fail to function not because China is unwilling to sabotage but because they’re incapable of causing significant damage. The most likely way I expect this to happen is that algorithmic efficiency improvements over the course of the 2030s make training to an RSI-capable model increasingly less hardware reliant, at which point it becomes easier and easier for the US to stash the requisite amount of dark compute. At current rates of efficiency improvements (about ~3x a year) you’d see a model with a billion dollar training run to cost just $4 million five years later, and I expect more AI r&d work (either from humans or models) to increase that number over time. Still, this delay might be enough to make a coordinated project more attractive.

General thoughts:

Multiplying my probabilities directly gives me ~60% (for lower tier MAIM, extreme MAIM is only ~17%), although in practice I expect that these are very highly correlated (ie, if China is pursuing a persistent cyberattack campaign, it’s probably because they see it working). Without much investment in mutual vulnerability or verification, my default expectation is that we see a persistent but low-level MAIM regime function for a few years. During this time, the US and China both make relatively smooth progress on capabilities research and algorithmic efficiency, growing more concerned about their domestic projects and their international rivals as they see dangerous capabilities emerge. But because the capability gradient stays smooth, there’s no clear flashpoint for escalation and states default to continuing cyberops.

This regime will probably collapse in one of two ways:

- The first is that the price to train a model falls too far, making adversarial verification too cumbersome to support intervention. It becomes possible to train a model capable of RSI on a secret blacksite, such that the Chinese government only becomes aware of the project when the training run is already partway through or even complete. Seeing this, the CCP might give up on sabotage and slam on the gas internally, banking on staying close behind through theft and investments in offensive deterrence.

- The second failure mode is that hardening in response to cyberattacks becomes too effective, and China is reluctant to escalate further to compensate. For example, once AI coding agents are doing all the labor, they might be able to provably test their entire codebase and eliminate the need for human workers (and thus the best options for human intelligence). The Chinese government then reasons that its best move is to instead accelerate its own project and try to maintain parity that way.

Basically, I expect superintelligence to get delayed by at most a few years, limited mostly by adversarial sabotage instead of a mutual commitment to slowing down. Once the vulnerabilities that make MAIM possible fade, we quickly get a fast takeoff, likely in secret and under high pressure.

Max Räuker's avatar

Really appreciate the summary and discussion, Oscar.

Reading your notes on whether the Chinese government will expect to be disempowered by ASI, I feel significantly more sceptical than your 70% suggest.

I think it's useful to even more explicitely avoid the "unified actors making coherent decisions" assumption.

I vaguely think of the relevant CCP actors as a group of relatively old successful party-hierarchy-climbers led by the party leader in a relatively authoritarian style, advised by tech and military leaders on relevant issues.

I think it's unlikely that such a group will be very confident that ASI will disempower their rule.

* It is too outlandish for people who are not drinking the ASI koolaid on the regular, especially when there is no clear evidence for the threat vector (e.g. via the US using their frontier AI systems to engage in dominating and destabilizing actions).

* I think Chinese tech firms will continue to make progress on AI research and keep at the frontier in my dimensions of a very ragged and multidimensional capabilities frontier ➔ overconfident tech leaders can always make CCP leadership feel confident about Chinese AI capabilities, it will always be very easy to tell yourself that you're competitive and "only fairly close behind", aka we won't be easily outmatched on AI, let alone more generally

* I think the U.S. government wouldn't disempower the CCP once they develop ASI, and that this is what a reasonable Politburo member at the CCP should believe as well? One could make comparisons to the conflict with Venezuela now, but it doesn't seem like the CCP will consider themselves a possible future Venezuela given ASI?

I think they will consider the possibility of disempowerment and track it, but not take it as given to the degree that you suggest, and likely not to the degree that they would risk initiating a war over it.

(Sorry for the hasty writing, and greetings from Berlin!)

6 more comments...

No posts

Ready for more?