Sign in

norabble.substack.com

@norabble.substack.com
14 followers 11 following 78 posts

An IT professional and software architect, with 30+ years of experience, ex-AWS, with a history advising clients in the financial industry. Author of substack.norabble.com.

PostsRepliesMedia
norabble.substack.com @norabble.substack.com · 29/09/2026
Every open model stays available, so model choice stays as broad as it is today. substack.norabble.com/p/trusted-d...
substack.norabble.com
Trusted Deployers
How to keep dangerous AI out of reach while preserving model choice
000
norabble.substack.com @norabble.substack.com · 29/09/2026
Above a dangerous-capability threshold, weights go only to certified deployers: operators who secure the weights, run guardrails against malicious use, don't allow fine-tuning that strips out refusals, and close accounts that show abuse patterns. Below the threshold, nothing changes.
100
norabble.substack.com @norabble.substack.com · 29/09/2026
When we discuss changing that the debate is usually framed as two options: ban open weights, or keep posting them for anyone to download. My proposal for preventing AI misuse sits between banning open-weight models and posting them for anyone: Trusted deployers.
100
norabble.substack.com @norabble.substack.com · 29/09/2026
They have neither the compute, nor the interest in the complexities of deployment. Do we need to public access to the model files then? Public access opens the door to unsafe deployments and malicious use.
100
norabble.substack.com @norabble.substack.com · 29/09/2026
Most people who use highly capable open-weight AI models have never touched the weight file. Users reach models through APIs deployed by someone else.
100
norabble.substack.com @norabble.substack.com · 22/09/2026
I also make my case for action. Why and what. These effects don't need to be drastic. AI's promise can survive the pursuit of safety. Delays in enabling coordination force starker future choices from a narrower menu. substack.norabble.com/p/enough-re... #AISafety
substack.norabble.com
Enough Reason to Act
You don’t need to believe everyone dies. Staying in control requires understanding, coordination, and foresight. Eight failed arguments, why they fail, what we can do together, and why.
000
norabble.substack.com @norabble.substack.com · 22/09/2026
I spent the last few weeks cataloguing the arguments people use to avoid the AI risk debate. It's mostly not bad-faith, but the distraction is no less. I found eight.
100
norabble.substack.com @norabble.substack.com · 22/09/2026
AI policy is in its infancy. Calls for a direction are coalescing. But cynicism, and other distractions are avoiding the core questions.
100
norabble.substack.com @norabble.substack.com · 01/09/2026
substack.norabble.com/p/every-rew... #Cybersecurity #AISecurity #AIAlignment
substack.norabble.com
Every Reward Bends
An incentive program for security work, and cross-over lessons from OpenAI’s Hugging Face incident
000
norabble.substack.com @norabble.substack.com · 01/09/2026
The agents tried to corrupt their transcripts and escape their containers so they could spoof tool calls. They were gaming level one, focused on the scorer. This demonstrates how indirection can contribute to successful defense. Staying one layer ahead is necessary. If you can't, you need to pause.
100
norabble.substack.com @norabble.substack.com · 01/09/2026
Agents under a reward bent toward the reward, the way teams under a metric do.
100
norabble.substack.com @norabble.substack.com · 01/09/2026
The lessons here share a lot with those surfaced by the technical reports of the OpenAI Hugging Face incident. The comparison explains both sides better than either alone, so I brought it in. The failure modes were the same ones.
100
norabble.substack.com @norabble.substack.com · 01/09/2026
With this in mind I wrote about managing an internal incentive program for security. It's more a template than a structure, but I hope it inspires.
100
norabble.substack.com @norabble.substack.com · 01/09/2026
Security backlogs are more critical than ever. We can talk, but how do we translate that to action? Organizations resist change. So you reward them for it. But that reward will bend. You'll get some of what you sought, but something else too, and over time, less of what you sought.
100
norabble.substack.com @norabble.substack.com · 17/08/2026
substack.norabble.com
Why It Hasn't Happened Yet
The protections keeping capable AI away from malicious intent are weakening. What developers and software companies should be doing now, with old techniques and new ones
000
norabble.substack.com @norabble.substack.com · 17/08/2026
That leaves conventional security. I wanted to explain this state in a deep enough way to be meaningful, and provide tools to build the priority to do what needs to be done. Full piece: substack.norabble.com/p/why-it-has...
substack.norabble.com
Why It Hasn't Happened Yet
The protections keeping capable AI away from malicious intent are weakening. What developers and software companies should be doing now, with old techniques and new ones
100
norabble.substack.com @norabble.substack.com · 17/08/2026
Open-weight releases put the first three at risk. Classifiers depend on deployments. Abuse detection depends on monitoring and bans. Alignment is a weak protection, and weaker yet when fine-tuning is allowed.
110
norabble.substack.com @norabble.substack.com · 17/08/2026
The HuggingFace Incident shows AI attacks are possible, why haven't you seen them? — training alignment — security classifiers — abuse detection at the labs — your own conventional security You can hope and pray the first three are done right, but the fourth is what you can control.
120
norabble.substack.com @norabble.substack.com · 05/08/2026
We are learning of so many cases where monitoring of cybersecurity evals wasn't done. Both hard to believe and unsurprising from another PoV. We need to redouble our efforts. Labs must have standards. Priorities must be set. substack.norabble.com/p/nobody-was...
substack.norabble.com
Nobody Was Watching
Two labs skipped monitoring on their cyber evals. The same week, a hundred companies signed a letter supporting deployments that can’t be monitored.
000
norabble.substack.com @norabble.substack.com · 05/08/2026
We need to take security more seriously. OpenAI, Anthropic, and more are demonstrating this with their own missteps. Transparency is key here. If I appreciate anything here it's that. We must allow for honesty. I explain, in my latest post, my most widely read so far.
100
norabble.substack.com @norabble.substack.com · 23/07/2026
OpenAI patched the sandbox flaw. Sandbox fixes are not enough. The response should be many layered. Alignment is the big picture. More are in between. I discuss observer models, and ask, where were they? What is the standard for internal model deployments? substack.norabble.com/p/an-openai-...
substack.norabble.com
An OpenAI Model Escaped Its Sandbox. Where Was the Observer?
OpenAI accidentally hacked Hugging Face. A basic layer of defense appears to have been missing, and no one has explained why.
020
norabble.substack.com @norabble.substack.com · 21/07/2026
Why does the definition matter? "Slop = AI" sells a quick fix: an AI-detection filter. The harder, better fix goes untouched—feed algorithms optimized for ad revenue, not for us. #AI #writing substack.norabble.com/p/the-perpet...
substack.norabble.com
The Perpetrator Is Not the Tool
A better definition of slop points to feed control as the priority.
020
norabble.substack.com @norabble.substack.com · 21/07/2026
The recruiter strapped to the desk isn't the perpetrator. The leader who arranged it is. The recruiter is the tool. AI is often the tool too. But the perpetrator is never the tool.
100
norabble.substack.com @norabble.substack.com · 21/07/2026
Run the test on a real example. A recruiter cold-calls to read a script and ask four things already on my resume. No AI in sight—but it's lazy, a numbers game dressed as personal attention, and it wastes my time. That's slop.
100
norabble.substack.com @norabble.substack.com · 21/07/2026
A more useful definition points at three things instead: laziness (someone stopped putting in appropriate effort), manipulation (a purpose misaligned with the audience), and cost shifted onto the reader.
100
norabble.substack.com @norabble.substack.com · 21/07/2026
The problem: if "AI-made" or "digital" is baked into the definition, and slop is always a slur, then we're committing to calling a lot of genuinely good work bad.
100
norabble.substack.com @norabble.substack.com · 21/07/2026
We've quietly agreed that "slop" means "content made by AI." I think that definition is a trap. And it's steering us toward the wrong fix. 🧵
100
norabble.substack.com @norabble.substack.com · 30/06/2026
The medical consensus says pervasive testing fuels overdiagnosis and hypochondria. I get the worry—but it misses how data compounds. One cheap test is noise; a decade of them is signal. My case for cheap, pervasive testing: substack.norabble.com/p/more-data-... #healthtech
substack.norabble.com
More Data, Please
Rethink Medical Backlash Against Pervasive Testing
000
norabble.substack.com @norabble.substack.com · 23/06/2026
Everyone has a hot take on #AI. Awareness of the reality of software development outside the field is skin deep. On screen, programmers appear ~300x less than doctors. That gap could be smaller, if we tried. substack.norabble.com/p/the-invisi...
substack.norabble.com
The Invisible Profession
Opinions about AI are outrunning our understanding of the software beneath it
000
norabble.substack.com @norabble.substack.com · 16/06/2026
Six months ago I mapped the AI build-out as a four-layer gamble. Six months later significant hurdles are passed, but there's more to come. Capex is racing $410B → $700B → ~$1T. Today's revenue justifies last year's bet, not next year's. substack.norabble.com/p/the-ai-gam... #AI #AIbubble
substack.norabble.com
The AI Gamble, Six Months On
A layer-by-layer look at the AI value chain — chips to applications — finds firmer footing on capex, but a mountain only half climbed.
000
norabble.substack.com @norabble.substack.com · 10/06/2026
No commenter has yet demonstrated an engagement with my ideas.. so in terms of signaling interest in another person I think I'm winning so far.
000
norabble.substack.com @norabble.substack.com · 10/06/2026
I'm not going to hire an artist for something I'm not paid for. So, yes, it's a few minutes with an image generator, expressing my idea, and getting a result. The rest of the time goes into the writing.
100
norabble.substack.com @norabble.substack.com · 10/06/2026
What would the other options be? I could drop some stock image, that means nothing. I could use no image, though this is proven to get less engagement. If people end up more attracted to a post with a handmade image that's superb, sure, that's fair.
100
norabble.substack.com @norabble.substack.com · 10/06/2026
"No" is a bit extreme. But it's not meant to be a Michelangelo. It's a small item to attract to post about a concept. Now, you might say, I should expect anti-AI bias and work hard to avoid it. But in this case, the anti-AI bias reactions to the image do a great job is illustrating the concept.
100
norabble.substack.com @norabble.substack.com · 09/06/2026
If you spent as much time on my post as you spent looking through that image for something to critique, you might have had something interesting to say. You're just acting as a content police with AI shaming.
200
norabble.substack.com @norabble.substack.com · 09/06/2026
You are signaling no engagement with my thought. I've listened to George's podcasts and know he'd not have your reaction. He has a point, but it's not that an AI generated images are evil.
220
norabble.substack.com @norabble.substack.com · 09/06/2026
And if you didn't?
000
norabble.substack.com @norabble.substack.com · 09/06/2026
Spend measures effort, not progress. Significant work takes time to find its direction. A pullback wouldn't confirm value was never there. Full piece: substack.norabble.com/p/are-we-in-... 5/ #AIeconomics
substack.norabble.com
Are We in a Token Bubble?
The wrong question — and a better one for reading the AI boom.
000
norabble.substack.com @norabble.substack.com · 09/06/2026
What falls out explains the 'is this worth it?' conversation. The most visible usage, tokenmaxxing and splashy demos, is the least valuable. The most valuable work now is overlooked: security patches, reliability fixes, the tech-debt ~90% of users take for granted. 4/
100
norabble.substack.com @norabble.substack.com · 09/06/2026
To tell them apart, I built a tool I call the Ingenuity Matrix. It sorts usage on two axes: scope (naive / simple / significant) and social alignment. Does the work create value, merely move it, or destroy it? 3/
120
norabble.substack.com @norabble.substack.com · 09/06/2026
Start with the metaphor. 'Bubble' smuggles in two assumptions, that it's one thing, and it ends by popping. Neither holds. Industrial booms deflate, and when they run out of air, they leave a structure behind. The useful question: which part is air, which is structure? 2/
100
norabble.substack.com @norabble.substack.com · 09/06/2026
The AI bubble debate has a new form: the 'token bubble.' Coming from software with a long interest in economics, I think the framing is off before we get the evidence. A thread on what's actually going on. 🧵 1/
substack.norabble.com
Are We in a Token Bubble?
The wrong question — and a better one for reading the AI boom.
120
norabble.substack.com @norabble.substack.com · 09/06/2026
But because this debate often gets off track, I feel compelled to mention trivial signs of AI aren't confirmations of lack of thought. substack.norabble.com/p/the-slop-s...
substack.norabble.com
The Slop Scapegoat: AI
Blaming AI for low-quality content misses the real problem—and the real opportunity.
100
norabble.substack.com @norabble.substack.com · 09/06/2026
Because I respect you, I'll assume this is truly out of context junk, that would have seemed off in the same way as a old school form letter slop, not just a pangram detection.
substack.norabble.com
The Slop Scapegoat: AI
Blaming AI for low-quality content misses the real problem—and the real opportunity.
400
norabble.substack.com @norabble.substack.com · 09/06/2026
To be fair, this story could have replaced "AI-generated pitch", with "form-letter". This guy wrecked a potential connection, many ways to do that. The reasons behind it are probably the same, they don't see the value or cost. The form changes slightly.
110
norabble.substack.com @norabble.substack.com · 02/06/2026
Hiring became a war nobody declared. Employers filtered to cut costs. Applicants gamed the filters. AI removed the last natural brake. Now it's a prisoner's dilemma, one-sided fixes only escalate it. The exit is collaborative. substack.norabble.com/p/hirings-ac... #hiring
substack.norabble.com
Hiring's Accidental War
One-sided fixes become weapons. The exit is collaborative.
000
norabble.substack.com @norabble.substack.com · 27/05/2026
I'm not sure anyone has actively tried to bring hiring companies and candidates needs together. Candidates do hinky things like mass applications, but recruitment teams do hinky things too, like dead applications, or illogical filters: substack.norabble.com/p/or-equival...
substack.norabble.com
Or Equivalent Experience
Lazy Mistakes in Hiring and the Truth Behind Jobs Data
000
norabble.substack.com @norabble.substack.com · 27/05/2026
The truth is, you don't really need AI to apply for a lot of roles (100+). Maybe to apply for a stupendous amount of roles (1,000+). There's something to your comment, but there's more to the story than that. It's more an information gap.. don't know who's listening, so don't invest in filtering.
110
norabble.substack.com @norabble.substack.com · 26/05/2026
I funded this back in 2012 when it was fresh. Since then I've mostly stopped gaming, so even if they did release it now, I wouldn't have time.
000
norabble.substack.com @norabble.substack.com · 26/05/2026
'Bachelor's degree or equivalent experience' is logically redundant AND AI hiring tools exploit the ambiguity against candidates. New piece on why lazy hiring is getting worse — and why the recent grad unemployment panic is based on misread data: substack.norabble.com/p/or-equival... #hiring #skills
substack.norabble.com
Or Equivalent Experience
Lazy Mistakes in Hiring and the Truth Behind Jobs Data
001