Podcast Banner

Podcasts

Paul, Weiss Waking Up With AI

Containment and Counsel: The Sol Incident and AI and the Practice of Law

In this episode, Katherine Forrest and Scott Caravello open with the news of OpenAI models venturing outside of their isolated environment during an evaluation, then consider the emerging tension between the use of AI in legal practice, unauthorized-practice-of-law statutes, and the legislative efforts taking shape in response.

For the sources referenced in this episode, please see the links below:

New York State Senate: AI Impersonation Bill (S. 7263A)

U.S. District Court (N.D. Ill.): Nippon Life Insurance Company of America v. OpenAI Foundation et al

Stream here or subscribe on your
preferred podcast app:

Episode Transcript

Katherine Forrest: Well, hello, everyone, and welcome back to this week's episode of Paul, Weiss Waking Up with AI. I'm Katherine Forrest.

Scott Caravello: And I'm Scott Caravello.

Katherine Forrest: And Scott, I know, I know we have run the hat thing to ground, OK? So luckily we actually have a lot of other things to talk about apart from your hat problem. And it is a hat problem, right? It's just too many of them. But we're not going to talk about that and we're going to go on.

Scott Caravello: You know, I will say we should go on. I think I've been traumatized enough. But I did send a photo to one of our listeners who's also a partner. Shout out Jeff Osterman, who was curious about the hats. I gave what I thought was a very well-reasoned defense about the amount of hats that I have.

Katherine Forrest: Yeah, well, there you go. So we are saved from having to discuss the number of hats by, boy, some big events this week in the AI world and it's really hard to know where to start. Let's just do a quick introduction on what happened with OpenAI's 5.6 Sol, S-O-L, model and Hugging Face, and then go into our main topic, which is on the unlicensed practice of law and AI and this bubbling debate that's really been getting some traction. But I can't tell you how many emails I got from people who were really freaked out by what happened with the OpenAI Sol model's testing sort of excursion into Hugging Face this week.

Scott Caravello: It really is unbelievable. It is the first of its kind. It is all over the place. I know that we're going to talk more about this in depth in future episodes, but you know we've seen also a rapid legislative response with a proposed bill that would have developers implement a so-called shutdown mechanism in certain cases. So things are moving quickly on this front too.

Katherine Forrest: Yeah. So let's just sort of fill some of our listeners in who may have missed it if they were, you know, sort of in the South of France or vacationing in some far-flung wonderful place where they didn't hear about this. But essentially what was like a red teaming exercise that OpenAI was doing with its Sol model. It's 5.6 Sol model, which is the large model in the family that's part of 5.6. It actually had instructed in a sandboxed environment. So the model was put into an environment where it was not supposed to be able to escape. It was given some instructions to undertake some various kinds of security exercises to see what it was capable of. And the model, it is assumed, decided that it could actually score more highly. This is sort of what we think right now is the motivation of the model on these tests by not only executing on these issues that it was being tested on within the sandbox, but to actually do them outside of the sandbox. So the model, incrementally, which is exactly what Mythos did, incrementally found a vulnerability in some code and was able to sort of exploit that. You can think of it like Pac-Man where it sort of exploits the vulnerability, sort of eats the vulnerability to the end of a line and then finds another vulnerability to the right or to the left or to the upper, the down, and then sort of gobbles up that vulnerability and pushes incrementally in small little bites. It pushes it again and again and again until it was able to actually escape the sandbox, make its way into the open internet. And then on its own, it was agentic. And that's the only reason why it was able to do this. It was able to get into the Hugging Face infrastructure and that was not the intent of the OpenAI folks at all. So anyway, now there's this kill switch thing that we'll talk about in another episode.

Scott Caravello: Sounds great.