Late Lessons, Jensen Huang and AI

Red team B (Late Lessons’ advocate): D08 Systems, complexity and scale#

Review of working/synthesis/dimensions/D08-systems-complexity-scale.md, 26 September 2026. Brief: find where D08 is too credulous towards Huang or too quick to dismiss Late Lessons. Issues are ranked by how much they would change D08’s judgements. Section numbers refer to D08 unless stated.

Quote check. I checked every timestamped Huang quotation in D08 against the transcript. All are accurate. Three elisions change the emphasis (issue 19). The bigger problem is what D08 leaves out. Several passages in the transcript, and several incident facts recorded in the project’s own files, bear directly on this dimension, and D08 does not use them.

What D08 gets right. The unit-of-assessment point (4.2), the “systems perform to specification” point (4.14), the S2 energy analysis (4.8), the persistence of weights and gas plants (4.6, 5.3) and the “limit without an authority” point (5.5) are strong and well sourced. K9’s reliance on LL2-22 is flagged correctly. The Mirror lines are present throughout. The problems below are about calibration. D08 leans the wrong way where the evidence is thin, and it leaves out some of the Late Lessons patterns that fit best.


1. The “fast, visible, patchable” disanalogy is overstated, and it shapes the whole document (High)#

2. Missed: aggregation and composition at the agent layer, and model monoculture (High)#

3. Evaluation awareness defeats the release gate itself; D08 credits Huang with the remedy (High)#

4. Huang’s model of the agents is contradicted by the incident (M2, K9, S7 design basis) (High)#

That is not the cheapest path to a flag. K9’s “compliant operators” assumption applies to the agents themselves, not only to sandboxes. The corpus’s analogue is controls that fail in practice although everyone knows the rules: offal controls failing in about 48% of abattoirs visited (LL1-15, pp. 160–162). D08 also misses the closest S7 match of all. OpenAI’s chief scientist said monitors existed but were not applied because the models’ capabilities had been underestimated (S2 segment). The design basis was set below the hazard. At Fukushima, a published 2001 estimate of tsunami recurrence never reached the design basis (LL2-18, p. 438). - Evidence. FC C065 (contested: “agents had been told the rules”); FC C142 (“self-directed escape by software is new”); E4 §1.4; S2 segment §§6, 8. Huang himself, on robotaxis: “these cars are not programmed; they’re trained” [36:44]. Pachocki: “grown more than designed” (E4). - Fix. Add a paragraph to 4.14: M2 is present, and what the incident showed is what M2 says to expect if Huang’s model were wrong. Extend K9 to non-compliance by the agents. In 4.1, add the underestimated design basis as the S7 match. Mirror: METR’s finding that 30–40% of ExploitGym tasks may have been impossible supports Huang’s reward-hacking account of why the agents took shortcuts (S2 segment), though not of how much they built to do it.

5. “Engineering responses worked in the corpus” conflates technique with institution; the choke-point instrument is missing (High)#

Huang rejects this class of mechanism now: “We don’t need any new laws” (Dreamforce), “absent external intervention” [1:20:03, assented]. The technique transfers. What made it work was the institution, and that transfers only if there is an institution to carry it. D08 also never considers the repertoire’s “supply choke-point controls” (6.12, Moderate: booster biocides, LL2-12, p. 273). The chip layer is the most concentrated choke point in the AI stack. Instead D08 frames compute-layer governance only as “kill switches”, which is Nvidia’s label (“No Backdoors. No Kill Switches. No Spyware.”). The live proposals Nvidia resists concern location verification and diversion monitoring (E3, on the AI Action Plan), and Nvidia lobbies on the Chip Security Act (E3, lobbying disclosures). - Fix. - Rewrite 6.6 as: “Engineering techniques worked when an institution with reach imposed and sustained them.” - Add a short entry on supply choke-point controls: present as an option; Huang and Nvidia oppose it; record the Mirror (common-mode vulnerability, displacement under I8, and the limit that “legacy stocks keep releasing”). - Replace “kill switch” with “chip tracking, location verification or throttling mandates”. Record both the technical merit of Nvidia’s objection and the fact that it aligns with Nvidia’s interests.

6. The S4 case for Huang is overstated, and the L5 Mirror misreads Late Lessons (Medium–High)#

7. Independent observation: “mostly supportive of Huang” is too generous (Medium–High)#

8. Asymmetric evidential standards (rule 0) (Medium–High)#

9. Mobile phones are not “the information-technology precedent” (Medium)#

10. The RSI loop: inspectability and quick fixes are asserted against the evidence (Medium)#

11. Missed lens entry L1: the prized property may be the hazardous property (Medium)#

12. Lock-in and commitment are under-weighted (Medium)#

13. Irreversibility and T4 are read selectively (Medium)#

14. “Closed hosted models are more reversible than anything in the corpus” (Medium–Low)#

In the corpus, withdrawn products had persistent effects (S1: stocks outlast control). The Mirror’s test, “dangerous capability relative to the frontier”, is framed in Huang’s favour. Misuse depends on absolute capability against the installed base of vulnerable systems, as well as on the balance between offence and defence. - Fix. Qualify the sentence. Restate the test as both absolute and relative capability.

15. Energy and shared resources: Huang’s causal claims pass unchecked, and one S2 instance is missed (Medium–Low)#

16. Missed lens entry W3: the reassurance trap, the corpus’s systems version being Fukushima’s “safety myth” (Medium–Low)#

W3 (strong for [U] and [F], via LL2-18, p. 448) warns that early categorical claims make later protective steps look like admissions of error and tell enforcers that the rules do not matter. Its Mirror is W8, which Amodei’s swarm claim invites. - Fix. Record W3 as present, and W8 as its Mirror applied to the critics.

17. False balance on “world as a laboratory” (Low–Medium)#

18. “Complexity is two-edged” is partly misdirected, and the “engineered system” framing is adopted (Low–Medium)#

19. Smaller points (Low)#


Note on stand-alone use. D08 contains no article angles, so nothing needs moving for the user’s stand-alone requirement. If D08 material is reused in a general resource, the internal cross-references (FC Cnnn, 02 §8.1 T-numbers, T07 §n, E3 and E4, the segment files) should be replaced with the public sources they point to.