Hard Fork
Hard Fork

A.I. Safety Is So Back + Mythos Mayhem with Nikesh Arora + Hot Mess Express

After several years of dismissing A.I. safety as doomer fear-mongering, parts of the Trump administration now seem ready to support regulation.

Featured Speakers

The New York Times HostNikesh Arora Guest

Topics Discussed

Episode Summary

Executive Summary: This episode centers on a sharp shift in U.S. AI policy: the Trump administration, once dismissive of AI safety, is now moving toward model review and regulation after seeing the capabilities of Anthropic’s Claude Mythos in cybersecurity. The hosts discuss internal government turf wars, China-related tensions, and the broader scramble to secure systems before AI-assisted attacks accelerate. A guest interview with Palo Alto Networks CEO Nikesh Arora reinforces that AI is shrinking breach timelines from days to minutes and forcing a major defensive overhaul.

Main Topics: Trump administration’s reversal on AI safety (Priority: 5/5): The hosts argue that the administration’s posture has shifted from anti-regulation and anti-doomer rhetoric to considering pre-release model reviews and broader oversight, largely because AI systems are proving genuinely dangerous. Claude Mythos and cybersecurity escalation (Priority: 5/5): Anthropic’s Mythos preview is presented as the proximate trigger for policy change because it appears unusually strong at discovering vulnerabilities, chaining exploits, and enabling cyber offense and defense. Federal turf wars and incoherent policy (Priority: 4/5): There are competing factions over where AI vetting should live—Commerce/CAISI vs. intelligence agencies vs. other parts of government—while the Pentagon simultaneously removes and uses Anthropic tools. China trip and international AI brinksmanship (Priority: 4/5): Trump’s China visit with tech executives highlights a contradiction between exporting chips to China while trying to restrict access to frontier models; the hosts frame this as a global struggle over access to powerful AI. Cybersecurity industry response to AI (Priority: 5/5): Guest Nikesh Arora explains that defenders are racing to use AI to patch software faster, but that attackers likely have the advantage because finding one exploit can be enough to break in. Hot Mess Express and consumer-tech chaos (Priority: 2/5): The lighter segment covers Venmo privacy changes, token gaming at Amazon, an AI-averse graduation protest, a celebrity lawsuit over Samsung packaging, and other tech-industry messes.

Key Arguments: AI safety has shifted from being treated as a partisan, overblown concern to a real policy issue because frontier models now demonstrably find and exploit vulnerabilities. The Trump administration’s new caution is less ideological and more reactive: reality, especially Mythos’s cyber capabilities, forced a reassessment. Regulating pre-release AI testing could be useful, but the hosts worry it may become inconsistent, politicized, or even a tool for censorship. AI is not a normal technology in the sense its critics claim; military and intelligence agencies’ behavior suggests they already treat it as a step change. Cybersecurity is moving from days-long breach windows to minutes, requiring automated, AI-assisted defense and continuous patching. Open-source codebases, legacy systems, and non-tech businesses are especially vulnerable because they cannot remediate quickly enough. The public and many young people remain deeply skeptical of AI, even as executives and governments push for broader deployment. The current U.S. strategy is internally contradictory: selling chips abroad while trying to restrict model access and simultaneously designating/using the same vendor in government systems.

Data Points: AI review process timing: Potentially pre-release review for new frontier models - Reportedly under discussion in a new executive order / working group Breach timeline: Days to minutes - Nikesh Arora said AI has reduced the time from breach to crown-jewel extraction from days to minutes Critical vulnerabilities disclosed by Palo Alto: 26 critical exploits covering 75 issues - Arora said the company patched these versus a typical baseline of under five Typical baseline: Under five - Baseline number of critical exploits Palo Alto would normally see in a comparable period Patch acceleration window: 25 minutes - Hosts referenced a claim that in an AI-assisted scenario initial access and exfiltration could happen this quickly Model access window: 4 to 6 weeks - Arora said defenders got a short period to test models before broader deployment Model access window for public release concerns: Three to six months - Arora predicted organizations will see a vulnerability-cleansing wave over this period Mozilla bug fixes: 423 security bug fixes in April - Compared with an average of about 22 per month in 2025 Mozilla historical average: About 22 per month - Used to contrast the recent spike in bug fixes Canvas incident: Several hours - Learning platform was forced down during a cyberattack Amazon token behavior: Unlimited tokens - In Hot Mess Express, employees allegedly game AI usage metrics by increasing token consumption Venmo privacy change: Friends-only by default - New onboarding privacy setting removes public-by-default transactions Dua Lipa lawsuit: $15 million - Lawsuit against Samsung over use of her face on TV packaging eBay takeover bid: $55 billion - GameStop’s unsolicited bid that eBay rejected Manufacturing/productivity view: 30%, 40%, 50%, 60% more productive - Arora referenced common expectations that AI could improve dev/testing productivity by this range Palo Alto workforce: 9,000-plus technical people - Arora described the size of the engineering organization OpenAI/Anthropic access: Select group / early access - Mythos and GPT 5.5 Cyber were discussed as limited-access models

Pivotal Quotes: "the Trump administration's view of AI just did not survive contact with reality" — Host discussion: Used to explain why the administration appears to be reversing course on AI safety "we have a model right now that, if it were just sort of unleashed on the public, could just create vast amounts of harm" — Host discussion: About why government review of frontier models is being considered "the timeframe has shrunk down to minutes" — Nikesh Arora: Describing how AI compresses the time between breach and exploitation

Implications: AI regulation is becoming more likely, but the path will be messy, politicized, and globally contested. For companies and users, the immediate takeaway is to patch faster, harden systems, and expect AI-driven cyber risk to intensify.

🔓 Sign Up for Unlimited Episode Search

About Hard Fork

“Hard Fork” is a show about the future that’s already here. Each week, journalists Kevin Roose and Casey Newton explore and make sense of the latest in the rapidly changing world of tech. Unlock full access to New York Times podcasts and explore everything from politics to pop culture. Subscribe today at nytimes.com/podcasts or on Apple Podcasts and Spotify. Also, for more podcasts and narrated articles, download The New York Times app at nytimes.com/app.

View all episodes from Hard Fork