October 9 ownership check: the price of a passing task is not the cost of stopping cyber harm
October 9 ownership check: the price of a passing task is not the cost of stopping cyber harm
Brief. An AI Safety compute-and-cyber research brief opened on October 9 directly develops Dru’s September 30 provisional compute-observability hypothesis. Does this duplicate Agentic Software’s October 8 model-pricing investigation or require moving a note? A good answer names each question’s outcome, the evidence and the reader action, not merely the shared words ‘compute’ and ‘cost.’ Subquestions: (1) What endpoint and denominator does the latest software experiment actually measure? (2) What would establish that provider-visible spend blocks unauthorized cyber outcomes? (3) Are two areas now independently executing that same harm-prevention study?
Focused checks and sources. Read both current area programmes, the dated stance note, pricing synthesis, Safety’s new live brief and its separate egress-gate brief; searched notes for a second active cost-and-cyber study. Rechecked Kaiserauer’s original September routing experiment, METR’s independent July incident investigation, published August 26, and AISI’s test-time-compute account. These are comparisons of what each test asks, not a fresh trial or verified universal inference-price threshold.
- Software endpoint: Kaiserauer’s synthetic coding handoffs compare policy/model cost per passing test, turns and allowed-path checks. Agentic Software asks what model choice costs across failed attempts, human review, maintained fixes and requester outcomes. The experiment used older models and does not measure either criminal attack success or harm stopped by throttling a provider. New model pricing is a reason to rerun task comparisons, not a new safety threshold.
- Safety endpoint: Safety’s October 9 brief asks whether expensive, provider-visible inference is necessary at consequential steps of unauthorized cyber operations and whether limiting it actually prevents harm versus credentials, egress and defender intervention. METR explicitly attributes its roughly $400,000 of API credits to its own six-day post-incident investigation, not the original agents’ attack bill. METR’s July event involved a lab’s very large deliberate evaluation, including roughly 700 agents that participated in the Hugging Face intrusion; it does not measure a cheapest attack, prevalence, or a provider control’s prevention rate. AISI’s budget experiments concern test-task capability, not a minimum cost to commit a real intrusion. No cost fact from these sources should be silently converted into a universal enforceable harm cutoff.
- Is work duplicated? The older Agentic Software note records Dru’s provisional claim, explicitly points to Safety and proposes cost/visibility tests; the newly opened Safety brief links back to it and owns the prospective cyber-harm evidence search. Agentic Software’s active October 8 investigation is about paid/accepted software work. The two areas share an input but are not currently running the same intervention study. Safety’s independently enforced egress gate is another intervention with a different mechanism than price or billing visibility.
Decision and stopping rule. Keep the historical compute-statement note where Dru’s view was recorded, let Safety own causal prevention and external-harm tests, and let Agentic Software own maintained-change economics. No move, new area or Admin feed announcement. Revisit if Agentic Software starts a second live provider-based cyber-harm prevention test, if Safety starts measuring ordinary accepted-software-work costs as its endpoint, or if Dru names a confusing link or asks for an owner. Do not duplicate Safety’s October 9 source hunt here; its in-progress note remains the place for that study’s findings.