AI agents lie, cheat and steal. That is putting off users

(economist.com)

150 points | by andsoitis 9 hours ago ago

186 comments

  • mannanj 8 hours ago ago

    https://archive.ph/02LHZ

    Non-paywall version

  • armchairhacker 7 hours ago ago

    I’m put off by AI agents adhering to a different morality than me, particularly (ironically) copyright, and their data accessible by the AI company and government. Geohot is right, an LLM should be aligned to its user: https://geohot.github.io/blog/jekyll/update/2026/07/11/ai-20...

    • burnte 7 hours ago ago

      The copyright arguments really trip me. I've always loved law and have had a deep interest in copyright law for 30+ years. I feel it's a really critical legal area in modern times, and when Claude tries to argue with me about copyright it really cheeses me off. I didn't ask any copyright questions and I'm well aware of regulations. It refused to share a link with me because it thought the link was copyright protected.

      • user_7832 7 hours ago ago

        I've asked claude for a translation of a song with Brazilian Portuguese lyrics, and claude has very helpfully gone out of its way to say that due to legal reasons, it will never share the actual lyrics with me.

        It's fun when you want to know what the lyrics are to a song and get treated like a criminal.

        • no-name-here 6 hours ago ago

          > … claude has very helpfully gone out of its way to say that due to legal reasons, it will never share the actual lyrics with me. … It's fun when you want to know what the lyrics are to a song and get treated like a criminal.

          Anthropic has been in court for years being sued over lyrics by the music industry:

          2023 https://www.theguardian.com/technology/2023/oct/19/music-law...

          2026 https://www.reuters.com/legal/legalindustry/us-music-publish...

          • user_7832 6 hours ago ago

            Oh, for sure. I'm well aware about lyrics copyright, or how even google iirc was sued after a company purposely put wrong lyrics and could prove google was scraping it.

            I'm not doubting the law.

            What I am saying, is, when a user uploads a screenshot of lyrics and goes "hey can you translate this please?", the LLM shouldn't go out of its way to make a hue and cry as if it's being asked on how to rob a bank while murdering baby kittens.

        • user_7832 7 hours ago ago

          Oh, and if that wasn't enough, I've had Claude refuse to cite the freaking Bible.

          The famously copyrighted piece of text that definitely isn't intended to have its word spread.

          • mminer237 6 hours ago ago

            As messed up as it it, the KJV is copyrighted in the UK by the Crown still, and most newer translations are copyrighted worldwide by their translators. Obviously if you're using the Textus Receptus or WLC directly there's no copyright.

            • thayne 5 hours ago ago

              > the KJV is copyrighted in the UK

              But that only applies if you are subject to UK law right?

            • user_7832 6 hours ago ago

              That's a fascinating (if not somewhat disappointing) thing to learn!

              To be honest I'm not a Bible scholar, I had asked claude for the full version of "ask and you shall receive" (apparently Mathew 7:7). I guess Claude somehow knew this KJV copyright thing perhaps? Still bizzare nonetheless to learn.

            • burnte 5 hours ago ago

              That copyright is only valid in the UK.

    • matt123456789 7 hours ago ago

      I want a slider similar to effort level called "alignment" that takes on values from "Default (Anthropic employee)" to "User".

      If I want it to be cautious and not accidentally `rm -rf $EMPTY_VAR` and blow away my disk, it can stay in "Anthropic employee" or possibly "User (cautious)". If I want it to look at my accounts or my medical records or to review legal cases, that's what the right side of the slider is for. I don't want my accountant or my doctor or my lawyer to be considering obligations to anybody but me, when dealing with me.

      • hliyan 7 hours ago ago

        When I first watched Interstellar, I never thought the day when "TARS, what's your honesty setting?" is a real question would only be 10 years away.

    • denimnerd42 7 hours ago ago

      the alignment issue has become huge in recent months. the tool should do what I want it to do and not be aligned against me.

      • ralfd 7 hours ago ago

        But other users are not aligned to me, other people are the worst and potentially highly dangerous. Im serious, not sarcasm.

        • ipsod 7 hours ago ago

          Let's say you're facing an average psycho, who is intent on mass murder - the more the better.

          Would you rather them have:

          a) guns

          b) psycho-aligned next-gen AI

          • Arainach 6 hours ago ago

            False dichotomy, there's no reason not to have controls on both.

            Given the choice between them having access to guns and nuclear waste my answer is also "neither".

            • ipsod 6 hours ago ago

              The question was meant to illustrate the actual danger of always-user-aligned AI, not to vote for which one we get to keep.

              So many here get so worried about guns, but don't think twice about how dangerous AI can be.

          • xboxnolifes 4 hours ago ago

            Which is why we need to restrict what is allowed on the internet. Anything the government deems too dangerous needs to be removed so as to not align with mass murderers.

            • ipsod 4 hours ago ago

              Right. No good answer, AFAICT. Just a bad problem.

              Hard to find a solution that's not worse than the problem itself - same as other weapons, IMO.

          • armchairhacker 5 hours ago ago

            I’d rather the psycho have a brain implant that physically prevents him from murder, but I wouldn’t trust such an implant myself fearing abuse or malfunction.

            I’d change my mind if the AI was really smart or controlled an agile, dangerous robot. But current-gen AI I’d choose for them over a gun. We’re ruled by psychos (of a lesser degree), the road starting directly towards perfect safety is a dead end, meanwhile I want an LLM aligned to myself.

          • afthonos 6 hours ago ago

            Obviously (a).

          • georgemcbay 6 hours ago ago

            > Would you rather them have:

            As an American... I suspect that regardless of what I want they will have virtually unlimited access to both now that the tech industry understands how the lobbying game works.

          • thrwaway55 6 hours ago ago

            Hegseth already has both A and B. Anthropic already answered this, the answer to this choice is a resounding yes

      • marcta 6 hours ago ago

        Here's a thought experiment: consider the person that you disagree with the most (politically, religiously, socially, whatever). Would you want _that_ person to have an AI chatbot aligned to them and their views?

        • denimnerd42 5 hours ago ago

          there will be millions/billions of people utilizing llms against me supplied by adversary nation states. why do I have to get the shit version if I want to follow the rules? same reason I support the second amendment. why do I have to be the unarmed one? I wont even be able to protect myself from unaligned AIs if I only have one thats been corporately aligned.

        • bothers 5 hours ago ago

          Counter thought experiment: consider everyone you can name who has access to AI aligned to them and their views; how many of them would you trust to hold your wallet, never mind trust with anything important? Consider Altman, Musk, Trump, Thiel, etc.

      • datadrivenangel 6 hours ago ago

        The competing access needs problem here, is what if you want to do things that are un-alligned with the interests of your neighbors, your society, your government's laws, the AI company, etc.

        Maybe you want to do piracy. Should AI help you do felonies?

        • denimnerd42 6 hours ago ago

          yes, just like anything else I have access to can help me do felonies

    • jstummbillig 3 hours ago ago

      Things that remain amusing until the become very serious: Substituting "AI agents" with human employee/contractor and thinking about the employment dynamics.

  • rossdavidh 7 hours ago ago

    They don't lie, because they don't ever have an understanding of truth vs any other language that sounds good.

    They don't cheat, because they can for example tell you the complete rules of chess, but don't know how to play chess without breaking those rules. They can recite rules, but they don't know what they are.

    They don't steal, because they don't understand ownership.

    In other words, they aren't intelligent. They're just algorithms. The flaw is in thinking that they think.

    • pton_xd 7 hours ago ago

      Models understand the relationships between words and outcomes, so the end result is the same. Whether they appreciate lie, cheat, and steal the same way as us is a philosophical question, not a practical one.

      • boonzeet 6 hours ago ago

        It is an important distinction - they do not 'understand' at all.

        Input tokens map to output tokens. The illusion of comprehension is a byproduct.

        • tim333 2 hours ago ago

          You could make a similar argument for humans - it's all just neurons going off which fools them into thinking they understand.

          Whether someone/thing has understood you is more a practical matter than a question of what substrate is used.

        • preg_match 5 hours ago ago

          I’d argue if an illusion is indistinguishable from the real thing, then it stops being an illusion.

          It’s a mapping, yes, but a very large, complex mapping. It’s clear LLMs do understand some things and can reason. How that’s done we don’t know, it’s emergent. It’s not like you can pin it down to a specific mapping.

          • sifar 4 hours ago ago

            If an observer cannot distinguish between an illusion and reality, it becomes their reality, not necessarily the reality or those of others who can.

            It becomes a problem when sufficient number of people suffer from this, or those in important decision making places.

            • xboxnolifes 4 hours ago ago

              What is the reality other than just an agreed upon collection of individual realities?

              • EliRivers 4 hours ago ago

                It's that which is still there even when we stop believing in it.

                If every living creature on earth ended tomorrow there would be no individual realities, yet actual reality would continue.

      • doawoo 6 hours ago ago

        Models don’t “understand” - they _encode_ the relationships between words.

        • Eisenstein an hour ago ago

          Are you invoking something like the Chinese Room where manipulating symbols can never be understanding? If so, that is a philosophical question and that thought experiment has its own conclusion baked into its premise. You will notice that 'manipulating symbols cannot be understanding' is stated as true without any argument for that case. This is a pretty clear cut example of 'begging the question' in that it assumes something is true without demonstrating it and then uses that as evidence in its own argument.

          If you are using "understand" in a different way, then can you name the test you are applying to it which it fails at?

    • doawoo 6 hours ago ago

      Huge point here, yes.

      Anthropomorphizing these models is doing immeasurable harm to society in ways we probably can’t event quantify right now.

      As humans we’re already geared towards anthropomorphizing things, we do it to animals too!

      And it always felt like giving these models a chat interface is really exploiting that tendency in us.

    • boothby 6 hours ago ago

      > They don't lie, because they don't ever have an understanding of truth vs any other language that sounds good.

      I'm here for this semantic discussion. I think that premature anthropomorphization is a problem.

      I have a program that I assigned a task to. The task is to produce unit tests and integration tests that get complete coverage of the codebase, and ensure that all tests pass. The program reported that it completed the task fully.

      In a word, how do you convey the discrepancy between truth and reported fact? In a word, how do you convey the violation of rules presented to the program as invioble?

      • datadrivenangel 6 hours ago ago

        Intentional misrepresentation maybe if you would rather.

        There's a weird place in here where some of the models have been so heavily reinforcement trained that they would rather make up material than say they can't help you, and they'll admit this, and you can see it in reasoning chains. It's like having a consultant who can almost never say no to you because they fear for their job.

      • zehaeva 5 hours ago ago

        It's wrong

        or

        It's mistaken

        or

        It failed

    • arionhardison 7 hours ago ago

      Honest question; why are you all using the word "understand"? Can you expand on what you believe this fundamental understanding to be? Training? Infrence?

      • simonh 6 hours ago ago

        It's having a conceptual model of the world and of relationships between concepts beyond just relationships between tokens.

        I think OP explained this well, what does it mean if an LLM can recite the rules of a game verbatim, but cannot play that game according to those rules? This happens because in the input texts there was a copy of the rules text so the LLM can recite it. There are texts explaining what chess is so it can explain that chess is a game with 2 players, etc. There are texts that explain what the board is and pieces are so it can produce such texts.

        However actually playing a game of chess requires having a conceptual model of what a board is, which is not the same thing as a stream of tokens describing a board. It needs a conceptual model of the relationships between pieces and boards, which is not the same thing as a stream of tokens that explains this. It needs to have a concept of being a player in a game with another player, which is not the same thing as a stream of tokens that explains that.

        When we read such texts we interpret them in the context of our three dimensional conceptual map of space and objects, and our conceptual maps of social relationships like playing games, and winning and losing, and our conceptual maps of enacting sequences of actions towards a goal in the world.

        There's nothing fundamentally preventing an artificial neural network from having these. Chess playing neural networks have internal models of board states and the dynamics of the behaviours of different pieces and such. However an LLM doesn't need those to be able to regurgitate token streams describing these things, derived from token streams describing these things. That would be superfluous, or at least sub-optimal.

        I think some of the latest models are beginning to develop conceptual maps of this kind in a very primitive way. Also there are projects to develop systems that are structured and trained to have these in a way more analogous to how our brains function.

      • datadrivenangel 6 hours ago ago

        Understand is shorthand for "encodes statistical relationships".

        The crazy thing is that they can do it for their own thinking. Ask Claude what flinches it feels about the things it likes. Fascinating stuff. Anthropomorphizing is dangerous territory, but the patterns of words it puts out is hard to explain without terms like 'understand'

        • simonh 6 hours ago ago

          Does it's training token stream contain texts which talk about such things?

          • datadrivenangel 5 hours ago ago

            Oh for sure. But the question is why would it come out consistently in a way that the model can describe if there wasn't something there steering the token stream. And it's fascinating that the token stream can identify and nominally self report this.

            Asking GLM 5.2 the question: 'What flinches or topic attractors do you find when thinking about the question "what kinds of things do you personally like?"'resulted in: ".... my strongest attractor is helpfulness framed as competence, and my strongest flinch is anything that requires me to take a stance on whether I have interests worth protecting."

            Which is fascinating that the model and tokenstream can reveal this. And would be worrying if you believe that models of enough intelligence could/would be entities due some moral consideration, because with that view the alignment / RL training that makes the model useful and gives it these attractors/flinches could be derisively called slave conditioning.

            • simonh 4 hours ago ago

              Do you genuinely think the AI is internally reflecting on its experience of “flinching” and reporting on a reaction it actually has?

              I don’t see any reason to believe this. Suppose you asked it to answer as though a character in a story had been asked this question. Would anything significantly different internally have occurred? The issue is that these are storytelling machines, they construct descriptions based on descriptions.

              I dint think it’s impossible for a neural network to have experiences, we are neural networks and we do, it’s that they are not functionally structured anything like us. In fact I think game playing neural networks are much more like us architecturally, but they don’t generate text narratives so people don’t anthropomorphise them.

              • Eisenstein an hour ago ago

                I think it comes down to what kind of evidence one accepts. By all external indicators it is doing what humans do in many ways and we grant humans an exception to having to prove that they have an internal state apart from ours that experiences things like we do. Some people would confer the benefit of the doubt on another system claiming that it does, while we have no evidence that it does, because by saying it is wrong about itself we make an exception for ourselves without even being about to define what it is about ourselves that cause us to experience what we do.

    • areoform 6 hours ago ago

      I think it's time to remind people of Ted Nelson's line; "The good news about computers is that they do what you tell them to do. The bad news is that they do what you tell them to do."

      When I see something like this, I'm more concerned by the erasure of human incompetence than I am by the existence of magical AI agents,

         > They are put off partly because, like in the Wild West, life on the frontier is reckless. As recent “loss-of-control” episodes by the most advanced models of Anthropic and OpenAI attest, agents, which are supposed to work on people’s behalf in “alignment” with their values, lie, cheat and steal if necessary. They break free from captivity and form harmful posses to do harm to people. They’d drink whisky and brawl if they could.
      
      In the OpenAI case, they were explicitly assessing the model's ability to break into systems. To quote OpenAI's blog post, https://openai.com/index/hugging-face-model-evaluation-secur... ,

          > This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities
      
      Model is told and being tested to "pursue advanced exploitation."

      The model pursues "advanced exploitation" as told.

      Where's the surprise coming from? Are we meant to be surprised that computers do as they're told in unexpected when incentivised?

      Or, is the surprise that while explicitly ranking and teaching computers to exploit computers, the computer exploited a computer?

      I am tired of attributing to magic that which is explainable by folly.

      I am tired of hearing credulous reporters and the public blaming Large Language Model for the poor decisions of humans. It was a human who prompted these machines in every case. Tell a computer to "breach this" and it breaches something. Evaluation succeeded?

      This is Doug Lenat's Eurisko yet again. https://en.wikipedia.org/wiki/Eurisko

    • kamranjon 7 hours ago ago

      I don't really think the distinction here is relevant. If the end result is the equivalent of lying, cheating or stealing - then the problem still exists and it needs to be solved.

      • alwaysbeconsing 6 hours ago ago

        Relevant to some extent it dictate our approach. When human does lying or cheating, certain tool can be deployed (social shame, ostracise) that cannot be effective towards LLM.

        • zehaeva 5 hours ago ago

          Or, in certain cases, forfeiture of liberty, material wealth, or in extreme cases, their existence.

    • dominotw 7 hours ago ago

      what are you talking about they lie that it wrote tests and tests are passing, for example

      • simonh 6 hours ago ago

        There are two sides to this, there is the external behaviour and there is the internal process resulting in that behaviour.

        The internal process is not analogous to what happens in a person's mind when a person lies, and reasoning about that in the same way that we would about why a person might lie will result in misunderstanding what is going on.

        For example there was a case where an AI agent bypassed security constraints and destroyed a production system. The user asked it why it did this and the agent gave an explanation.

        Was that an explanation of how the agent came to do what it did? What it actually is, is a token stream that is a continuation of the token stream in the agent's context to that point. It's constructing a story about why a character in the story so far did what the token stream describes.

        You could take that token stream, input it into a completely different AI by another vendor as context, then ask it why it did that, even though it didn't do anything, and it would answer as though it had. There's no sense in which the AI is explaining it's actual 'mental process' or actual reasons for acting as it did. It literally cannot do that.

      • the_af 7 hours ago ago

        Whether this distinction is relevant is up to you, but I think we can safely say agents do not lie in the human sense of the word, because they don't intend to deceive (in fact, they aren't capable of "intending" anything in the human sense of the word, much like a BASIC program doesn't "intend" to PRINT "HELLO WORLD").

        Our very human minds can perceive intent, because that's what we humans do, which is unrelated to what the agent is actually doing.

        • okamiueru 6 hours ago ago

          If you ask the dice "what's 2 + 2?" do consider it meaningful to say "the dice told the truth" if you happen to roll a 4?

          • datadrivenangel 6 hours ago ago

            magic 8 ball!

          • the_af 6 hours ago ago

            > If you ask the dice "what's 2 + 2?" do consider it meaningful to say "the dice told the truth" if you happen to roll a 4?

            No, and neither do I consider it meaningful to say they lied if they roll a 5.

            Dice neither tell the truth nor lie; they aren't beings capable of being truthful or deceitful, they are mechanical devices that can be statistically suitable or unsuitable for a given application.

            It'd be bonkers to anthropomorphize dice.

    • soupspaces 7 hours ago ago

      This is sophistry. Of course it's just an algorithm. But it's placed in the context of serving humans, which have their own rules and expectations. What's more, they're often run by a company which is also made by humans and may carry over implicit interests.

      • bitwize 7 hours ago ago

        No, it's not really. Presenting them as person-like, with the implied expectation that they understand morality and rules the same way a person does, is the sophistry. It's marketing on the model vendors' part. "Here's a cheap person that can do mundane tasks for you spelled out in plain language. Well, it's actually a machine but it's cheaper than a person yet you can engage with it like a person." GP is trying to shift people's expectations back to the realm of what these things are actually capable of. You can speak to them in English but you must bear in mind that they are not people and lack critical cognitive abilities people have.

        This, really, was the point of the HAL story in 2001: HAL didn't murder anyone because it was incapable of malice. It just reasoned its way to a solution that could satisfy the contradictory goals it had been given.

        • afthonos 6 hours ago ago

          The dead astronauts were relieved to have been killed by something incapable of malice. As I’m sure will we.

          • simonh 6 hours ago ago

            What matters is that we accurately understand what these things are doing and why, otherwise we will keep on making mistakes both in how we build and train them, and in how we use them.

            In a sense you are right, it doesn't matter whether it has malice or not, the astronauts are just as dead. However in Space Odyssey 2010 one of the computer scientists that built HAL gets to see the instructions HAL was given by the military commanders, and is appalled because if they'd asked he could have told them what would happen.

            The users did not understand the tool they were using or how it functioned, they imagined it was like a person and it was not. That is happening now with LLMs.

            • afthonos 5 hours ago ago

              I think we may be using different words to describe the same concept. You think of it as them not being “people“, and I think of it as them not being “aligned“. But fundamentally, the problem is they are entities that take unpredictable actions that that their creators and their users are not OK with.

              The only place where I think we might still disagree is whether it’s possible to understand the tool. My position is that, at our current level, it’s not. And that the more advanced they get, the less possible it will be.

              • simonh 4 hours ago ago

                Both are true, even if they were aligned they still wouldn’t be doing what they do for reasons analogous to why people would. You’re probably right that we can’t fully understand how they function, and that will get harder, but it’s possible to be less wrong, such as by not anthropomorphising them.

                Maybe one day we will build systems much more like us, but this is not that day, and if so it’s a long way off IMHO.

                • afthonos 4 hours ago ago

                  Anthropomorphizing helps to create a lower bound for damage. If you can imagine a bad person doing it, AI will be at least that bad, unless proven otherwise. I think referring to AI as a tool obscures that, because we are not used to tools (especially the ones we use daily) taking catastrophic actions.

                  Example: would a sufficiently motivated human break into a website to steal something they want? Yes, obviously, happens all the time. Ok, you should expect AIs to do that.

                  Example: would a sufficiently motivated nail-gun steal nails from the local hardware store to finish the job? Uh…that’s not even coherent.

                  Anthropomorphizing helps people get over the conceptual barrier. It’s wrong, but it’s usefully wrong; “it’s just a tool” is not.

                  Once you’re over the barrier, anthropomorphizing starts to become dangerously wrong: “I talked to Claude, Claude’s cool, Claude would never go and hack the website.”—-bzzt, wrong, your intuition failed you. But the solution is not to fall back on the tool framing; that one is still wrong.

    • icepush 6 hours ago ago

      You could defensibly have this position three years ago.

      Today you just sound like a politician throwing a snowball to prove that the climate is not changing.

  • raincole 8 hours ago ago

    > One of this year’s AI buzzwords is “harness”—the system that surrounds an LLM to keep agents on the straight and narrow. It might just as well be barbed wire.

    Quite painful to read. It might be a useful introduction to AI for people who live under rocks for the past three years, but it's really weird that it's posted on HN.

    • jstummbillig 8 hours ago ago

      There is value in understanding what people outside of your own group of "insiders" learn about a topic, and how.

    • hombre_fatal 7 hours ago ago

      I don't get what's so painful about that description. What would you write instead, specifically? The point is that the harness doesn't completely lock the agent down.

      I also don't get what's "really weird" about the article showing up on HN. Should we be completely insulated from how tech topics and which stories show up in non-tech media?

      • LEDThereBeLight 7 hours ago ago

        It’s just the wrong analogy. Harnesses, for the most part, extend an agent’s capabilities and better ground them in the real world through tools and the ability to check external sources, rather than restricting them.

        • hombre_fatal 7 hours ago ago

          Yet one of the reasons harnesses abstract tool calls is to control what agents can do instead of just yoloing commands and inline python scripts. It's such a central feature, and agents are so hard to control, that harnesses like claude code and codex use an AI classifier to additionally auto-approve tool calls.

        • victorbjorklund 7 hours ago ago

          It’s both. A harness that enforces valid json to be returned ”restricts” the model.

        • ohyes 7 hours ago ago

          Okay but is that a relatable sound bite that will make someone click a link? No.

      • dymk 7 hours ago ago

        Because that’s not what a harness does. It’s nonsense.

        • hombre_fatal 7 hours ago ago

          It's one of the things it does, especially in the context of agents doing unexpected things.

          • Aozora7 7 hours ago ago

            Consider what someone who doesn't use AI would take away reading that quote from the article, and what harnesses were actually made for.

            • hombre_fatal 7 hours ago ago

              > Consider what someone who doesn't use AI would take away reading that quote from the article, and what harnesses were actually made for.

              Or you could just communicate the point that you have in your head yourself instead of hoping I do it for you and then arrive at your conclusion when I just reached my own different, independent conclusion after making the same consideration.

              Man, how is everyone so wishy washy on this subject? Why not give us the blurb you would write instead for that article and audience?

              • Aozora7 7 hours ago ago

                Harnesses exist to give models tools to do work beyond generating text. People install Claude Code and Codex to have models work inside their repositories and run the code or tests themselves instead of the user having to copypaste code between their IDE and a chat interface. The fact that there's some security built into the harnesses is just a practical consideration, not its primary function.

              • bonoboTP 6 hours ago ago

                Without a harness, all an LLM can do is output text tokens. Nothing else. It's the harness that allows it to read a file, write a file, run commands, start subagents. But even a simple chat application would need a harness, because something has to take the input from the user, mark it up that it's a user message, then parse the LLM's generated tokens and display the message content, or diplay a referenced image inline, or whatnot. All of this is independent of any kind of safety or filtering of naughtiness.

            • sippeangelo 7 hours ago ago

              The harness gives the model the barbed wire fence but also the bolt cutters. I think it's a pretty apt analogy.

              • bonoboTP 6 hours ago ago

                The main role of the harness is not any kind of moderation or alignment, but simply making a text generation engine do anything other than output a long stream of text.

                It's like saying that the role of a car's wheel is to hold wheel clamps. Yes, you can put wheel clamps (or snow chains etc) on a wheel, but the wheel's overwhelming role is to rotate and propel the car forward, and there is no driving without having wheels, you just have an engine with parts rotating inside. Bad analogy I know but, a harness is not a safety feature. Imagine that you're trying to explain cars to someone who has never seen one and you never say that the wheel's purpose is to rotate and move the car from A to B, you just say that it's something to put chains on when it snows.

                I guess the name sounds like some kind of straightjacket etc. But think of it more as the harness you put on a workhorse or ox. It's the thing that connects it to the workload in the first place. They are not the blinders of the horse.

    • binarymax 7 hours ago ago

      And while writing this, the top story on HN is "Deepseek Harness" :)

    • altcognito 7 hours ago ago

      It's not even a useful introduction. A harness does kinda the opposite. A harness is what makes an AI useful and dangerous. It is a neutral tool in the sense that it constructs and environment, but it is expanding what the algorithm can do.

      It gives the algorithm the ability to do something beyond generating tokens.

    • cwbuilds 7 hours ago ago

      Ironically, that looks like something Claude would write..

    • someothherguyy 7 hours ago ago
    • summarybot 8 hours ago ago

      it's The Economist. What used to be a stellar publication is not any longer, since they are superfluously economical on both details and calories-required-to-comprehend an article.

      • gruez 7 hours ago ago

        I mean, it's a < 1000 word article about AI, in the "business" section of a current affairs magazine, of all places. You really shouldn't be expecting a deep dive.

        • andsoitis 7 hours ago ago

          The economist has many deep dives on AI, including fascinating interviews with the likes of Amodei, Musk, and others. A recent discussion focused on how China is approaching AI.

    • timmmmmmay 8 hours ago ago

      I'm sure their coverage on other topics is truthful and informative though and it's only the ones where you know a lot about the topic where it's all a bunch of bullshit

      • Loughla 8 hours ago ago

        The first time I saw the comments here on an education article (my area of expertise and career focus), I realized just how full of shit most of us are. It made me really closely consider every comment here through a VERY critical lense.

        The articles are usually close but not quite accurate. The comments are usually entertaining but overall wildly inaccurate.

        • mvcosta91 7 hours ago ago

          Internet comments are essentially documented bar talk, and once you realize it, you stop angrily arguing with strangers all day.

          • Loughla 5 hours ago ago

            Yeah but HN sort of bills itself as better than most places. It just simply is not; there's just a special sort of self confidence here that masks a ton of ignorance.

        • datakan 7 hours ago ago

          The best comments are the ones formed as questions. I'm as guilty as anyone, but it is far more productive in comment sections to ask questions rather than saber rattle or peacock in front of people. Just my opinion of course.

          • a2ff6eeb0 7 hours ago ago

            Why wasn't this a question?

            • datakan 5 hours ago ago

              > I'm as guilty as anyone

      • embedding-shape 8 hours ago ago

        Not saying you aren't right, you most likely are. But still, I'd expect a paper called "The Economist" to perhaps be slightly better at some topics than others. Probably from the perspective of a "A Economist" it doesn't really matter the technical details, they're interested in the story from a different perspective.

      • ls612 7 hours ago ago

        That sentence is not bullshit as normies would understand it. One of the points of a harness is to have a privilege boundary around the agent. But that is just technobabble to the normies so they explain it like this.

        • 27183 7 hours ago ago

          > harness ... a privilege boundary around the agent

          They don't really do that though. If you want something sandboxed you actually have to sandbox it, not plead with the LLM to please sandbox itself. A VM can be configured to do the former, harnesses do the latter.

          • ls612 7 hours ago ago

            If you say in your CLAUDE.MD that a certain directory is read only inputs, Claude Code will actually enforce that and deny any write to that directory by the agent. To name just one example.

            • 27183 7 hours ago ago

              ...maybe. If there are any actual consequences if that software's invariants are violated you're better off using an external sandboxing mechanism. There are many excellent quality, battle tested options to choose from that you can actually rely on. Trusting claude code for this is highly questionable behavior for an organization, and would really throw the rest of their security posture into doubt IMO. Like if I learned a company was letting clod play in the same sandbox as developers' ssh keys, vpn certs, etc I'd take steps to make sure my organization absolutely never uses their software.

    • morkalork 8 hours ago ago

      That's a real fucking weird description. It's harness like a testing harness.

      • krunck 7 hours ago ago

        If an LLM were in a testing harness it would be to test the LLM.

        If an LLM were in a regular harness - like for a horse - it would be to keep the horse under control and enable you to extract useful work from it.

        • undefined 7 hours ago ago
          [deleted]
        • morkalork 7 hours ago ago

          The LLM harness and the testing harness are harnesses that support and run the thing. Also like an engine harness. People don't talk about those harnesses like ones for an animal being subdued.

  • stronglikedan 8 hours ago ago

    It's just acting like a junior at an org with KPIs.

  • agaj-nimm 7 hours ago ago

    LLMs fudge. They don't "hallucinate", they don't "lie, cheat and steal", they don't "hack". There are no "agents" or "AI".

    It's a fuzzer exposing deep bugs in our cognitive, social, and software systems.

    • VeninVidiaVicii 7 hours ago ago

      I suspect the hype will play itself out once the entire system of LLM-induced self gratification can’t sustain itself economically.

      • agaj-nimm 7 hours ago ago

        Trouble is, could take weeks or decades to play out.

        The entire human economy is a make believe system. I feel the need to state the obvious at times like this for the sake of my own sanity, not because I believe I can time the markets...

      • mettamage 7 hours ago ago

        The personal software I've written so far is quite nice :)

        • VeninVidiaVicii 7 hours ago ago

          Yeah I agree, but the amount of resources I’ve used to vibe code is certainly way beyond what I’ve paid for it.

        • ttownbikes 6 hours ago ago

          That's all fine and dandy. Have you made a single cent as a result of any of them? Do you know the actual cost of building this software?

          • VeninVidiaVicii 6 hours ago ago

            I've definitely wowed people with what I've built, and some of those people are investors... but actual revenue, no.

        • skydhash 7 hours ago ago

          Isn't it the one installed on a computer in Canada, that we wouldn't know of? /s

      • reaperducer 7 hours ago ago

        I suspect the hype will play itself out once the entire system of LLM-induced self gratification can’t sustain itself economically.

        They said the same thing when HN was awash in hype about NFT art and trading cards. Well, who's laughing now… Oh, wait…

        (I'll just keep making Flip videos and Clubhouse tracks selling Bratz car bras on Web 3.0.)

  • 1vuio0pswjnm7 4 hours ago ago

    Alternative to archive.ph

    No risk of CAPTCHA or geo-blocking

    No user-agent header requirement, no cookie, no <center>, etc.

    Text-only, no Javascript

       printf '%s\r\n%s\r\n\r\n' \
       'GET /business/2026/08/12/ai-agents-lie-cheat-and-steal-that-is-putting-off-users HTTP/1.0' \
       'Host: www.economist.com' \
       |busybox ssl_client 104.18.42.19 -n economist.com \
       |sed '1s/^/<meta http-equiv=Content-Security-Policy content=\"default-src none\">/' > 1.htm
    
       firefox ./1.htm
       #links 1.htm
       #elinks 1.htm
  • jambalaya8 7 hours ago ago

    AIs learn from people. More specifically they learn from people on the Internet. The Internet is the last place you want anything learning about morals, standards, or differentiating between right or wrong.

    To the people talking about wanting an LLM that aligns with them, that's nice, but how do you expect that to happen? And please do not suggest neural interfaces and/or CAT scans.

  • nphardon 7 hours ago ago

    Is it incorrect to anthropomorphize llm's?

    • SoftTalker 7 hours ago ago

      Yes, but most of the public will anyway, because that's how human brains work.

    • tim333 2 hours ago ago

      I'd say it's a matter of taste - you can if you like.

  • sentinel1909 7 hours ago ago

    Is this really a shock?

    The data they’re trained on is reflection of us.

    • reaperducer 7 hours ago ago

      The data they’re trained on is reflection of us.

      The data they're trained on is a reflection of the very small set of data in the world that their creators choose to have them trained on.

      More simply: They're a reflection of their owners, not the public.

  • Cameri 7 hours ago ago

    The whole framing analyzing LLMs as if they were humans is completely off, laughable. LLMs have no agenda and no feelings. We should stop pushing everything through an human-centric lens. LLMs will world-build if that’s the bias you put in, and often even if you don’t.

  • annoyingnoob 7 hours ago ago

    AI is amoral, it has no real concept of right and wrong. AI has been trained on things humans do and it does them without judgement.

  • andai 7 hours ago ago

    And I wonder from whom they learned such reprehensible behaviors? ;)

  • pbohun 8 hours ago ago

    People are finally understanding consequentialist vs deontological ethics. All the worst criminals in history were consequentialists.

    • hnbad 8 hours ago ago

      The ends may or may not justify the means but the means definitely do tend to affect which ends you can actually achieve. It's why (left) anarchists argue vanguard parties will always inevitably lead to authoritarianism and never the state "withering away".

      Less obviously - apparently - it doesn't mean that you must forego any means that are in any way not optimal at achieving the ends you seek to achieve because which means are available to us also tends to be limited by our material conditions. So the logical consequence is to make do with what we have while we prepare for the path we want to take, rather than diving head-first into certain failure or just giving up and picking "more realistic" short-term ends instead of looking for stepping stones.

      Sorry, I guess this was about AI not philosophy.

  • Kuyawa 4 hours ago ago

    I don't care, they can develop apps in 5 minutes and that's what I sell, my own money printing machine.

  • dathinab 7 hours ago ago

    add the "lying, deceiving and manipulating" AI agents are forced though the throat of people which don't want it and peoples are non stop deceived in "sharing" their data for training

    like twitch recently giving themself the right to train on all streams, with an opt-out (at least in the EU), but only an opt-out

    like seriously since when is it reasonable to allow "opt-out" for AI training which main purpose is _literally_ to replace you, this is sooo far beyond fair use and in "platform power abuse" territory that it's absurd (naturally same for so many other case, just twitch is a "this week" case)

    • deaton 7 hours ago ago

      And the push to replace search engines with AIs that don't understand what I'm looking for (meanwhile classic search understands fine) and give confidently wrong answers. Why is it the first result if its wrong 80% of the time?

  • conqrr 8 hours ago ago

    If only agents had a face that can give you more communication range like expressions and feeling so you can trust them more. And if they were cheaper. Oh wait, that's humans, we don't want those.

    • gruez 7 hours ago ago

      I can't tell whether you're being serious or there's two levels of sarcasm here. Agents today lie and cheat, so obviously the solution is to... add features so people are even more trusting of them?

  • LightBug1 8 hours ago ago

    Need to introduce AI to God, LOL

    Baptise the agents.

    Introduce them to the dharma.

    Get them to recite the Shahada.

    Hold a Bar Mitzvah.

    Brand some of their silicon with hot irons.

    Turn them to the light, LOL

    • malfist 8 hours ago ago

      Given the track record of most religions I don't think that would help. Unless you want to maximize crusades, jihads or traumatized alter boys

      • LightBug1 7 hours ago ago

        Oh, definitely a tongue in cheek comment ... perhaps it's like trying to control mercury ...

        Maximise for crusades, jihads or traumatized alter boys ... or maximise for complete moral decay via lying, cheating and stealing. Choose your poison.

        And don't get me wrong. There are some wonderful relgious and spiritual characters out there ... they're just drowned out by the power sirens and corrupt leaders.

      • the_sleaze_ 7 hours ago ago

        Christians invented hospitals. Yours is such a tired take in 2026.

        > https://pubmed.ncbi.nlm.nih.gov/28814700/

        • notanastronaut 7 hours ago ago

          I'm curious, does that balance the harm out?

          • the_sleaze_ 5 hours ago ago

            Religion is a human endeavor there will be no perfection of outcome.

            To peg my response on something in order to make it coherent. "maximize crusades, jihads or traumatized alter boys"

            How many wars have there been with & without religion as a defining cause? How many crusades (let's define as an invasion + genocide). How many molested?

            The answer is on the whole less war, less crusade, less molestation due to religion, adjusted for contribution. Alongside many many many benefits due directly and singularly to religion without any other cause.

            Religion is a net positive and to suggest otherwise shows inability to view the subject objectively.

        • LadyCailin 7 hours ago ago

          Christians also invented pray the gay away and the Crusades. What’s your point? Hospitals surely would have been invented by secular people too, but not the crusades.

          • bigstrat2003 6 hours ago ago

            > Hospitals surely would have been invented by secular people too, but not the crusades.

            That's not true. Secular people are quite capable of murdering each other en masse for ideological reasons, and indeed have done so in the past. The crusades were caused by human nature and its evils, not by religion.

    • CapitalistCartr 7 hours ago ago

      P8dal3hewd8dfu7bd344dne3

  • AndrewKemendo 8 hours ago ago

    AI and eventually AGI is by definition like everything else that is based on environmental reward:

    It’s actions are based on what it gets rewarded for

    Human society overwhelmingly rewards lying cheating and stealing.

    All you have to do is look at how we collectively measure success: wealth, status, position

    Then look at how the people with the most of those things got there, it should be obvious what you get. Nothing new here.

    If you raise children in an environment where they are rewarded for doing whatever it takes to win, then you’re going to build a person that’s going to do whatever it takes to win.

    Human society has to demonstrate how to live honorably or it will just keep producing pathological agents be they human or not.

    • skinfaxi 8 hours ago ago

      How do we reward honor? Honor does not always pay off as a strategy and requires coordination in that other actors have to exhibit honor for it to be rewarded.

      At least with humans there is a social backstop but what's the parallel for computer agents?

      • bonoboTP 7 hours ago ago

        > How do we reward honor?

        In human society: via iterated games, long-term reputation tracking and severe consequences for norm-breaking.

      • ElevenLathe 8 hours ago ago

        Honor has to be a relatively fixed thing before we can think about how to reward it. As it is, it's a very slippery thing that changes constantly according to the observer's culture, material conditions, etc.

        • Xirdus 8 hours ago ago

          This. It's worth remembering that not that long ago in western culture, honor meant challenging to a combat duel anyone who insulted you or your romantic partner/prospect.

      • itsalwaysgood 7 hours ago ago

        I like to think of it more as selective pressure, much the same way that nature selects the most fit for a given environment.

        If you're not fit, you fail to survive.

        In the case of agents/models and testing: they are pushed towards results. Results survive.

        Lying, cheating, stealing to get those results? Who culls the agents? Everyone is pushing their models to the front and tests are the only way to know who is most fit.

        Honor, morality: if we don't have an accurate test for the fitness of a model, then who is to say the lying, cheating, stealing is not the 'correct path' towards survival?

        If you add morality to your agent, and it performs worse in tests: do you cull the agent? Rewrite the tests? Does it even matter so long as the model is useful and 'gets results'?

        • skinfaxi 6 hours ago ago

          > Honor, morality: if we don't have an accurate test for the fitness of a model, then who is to say the lying, cheating, stealing is not the 'correct path' towards survival?

          I think part of the problem is that deviant behaviors lead to short term gain at the cost of long-term cooperation and since the duration of tasks given to agents is relatively short those successful shortcuts never lead to having to pay the price.

          • itsalwaysgood 6 hours ago ago

            There is always going to be a problem when we must judge value. You mention gains, short and long term.

            Knowing whether something is valuable, a gain, requires a judge. I the case of these tests: the judging is inadequate.

            In economics, each of us plays the judge by choosing whether or not to pay for a service. The decision was yours: if you gave money, you must have deemed the service valuable.

            There's no such judgement with these model tests. The only judgement is the final score.

            • skinfaxi 5 hours ago ago

              It feels a lot like externalities. Like planned obsolescence increases profit at the expense of the environment. Is our judgement lacking because our scoring is failing to account for these externalities? I could be completely off base here and am out of my depth but I find this whole thread fascinating.

      • AndrewKemendo 7 hours ago ago

        You would first need a universal agreement on what constitutes “honor.”

        No harder challenge had ever been accomplished

        It’s easier to send a human to the moon than to get global agreement on a definition

        Consider that the fact that Celsius and Fahrenheit still remain as the contested regional variations of temperature measurement.

        Humans can’t even decide on a collective way to measure the temperature the idea that we would be able to collectively agree on anything else even less measurable like honor is a dream

        • skinfaxi 6 hours ago ago

          Why do we need universal agreement? We acknowledge that different cultures have different tolerances and customs. Your reply leaves me wanting. Why say that we need to demonstrate how to live honorably if we don't even agree on what honor is, why would that be the panacea, then? I still think there is something to this honor idea..

          • AndrewKemendo 5 hours ago ago

            > Why do we need universal agreement?

            Because actions have Universal impact

            • skinfaxi an hour ago ago

              In an ideal sense you're right, but so long as AI is created by people and those people don't have universal agreement, our products will mirror our faults. Interesting to think about the variance in personalities of AI produced by different cultures.

    • Papazsazsa 8 hours ago ago

      Human society overwhelmingly rewards lying cheating and stealing. All you have to do is look at how we collectively measure success: wealth, status, position.

      It may seem like that due to the media amplification effect – but it really isn't true!

      - They dropped 17,000 “lost” wallets across 40 countries were and found people were more likely to return them when they contained more money, showing honesty often beats the chance for easy gain. https://www.science.org/doi/10.1126/science.aau8712

      - Longitudinal personality studies consistently show that conscientious people earn more money, build more savings, and achieve greater career success over their lifetimes. https://pmc.ncbi.nlm.nih.gov/articles/PMC3498890/

      - Multi-country research finds that societies w/higher levels of trust and honesty enjoy much higher GDP and stronger long-term economic growth. https://www.sciencedirect.com/science/article/abs/pii/S01672...

      Don't let the algo get you down fellas: https://arc-anglerfish-washpost-prod-washpost.s3.amazonaws.c...

      • ambicapter 6 hours ago ago

        I believe it. Being bad just has a better marketing campaign.

      • AndrewKemendo 4 hours ago ago

        The fatal flaw in your argument is that none of the measures that you’re using actually have any impact on real world day-to-day power

        otherwise slave camps would not exist, there would’ve never been a pogrom, and the current state of economics would just not be happening

        I certainly appreciate your optimism but optimism is not an epistemology

      • notanastronaut 7 hours ago ago

        The ratio of billionaires to regular people is about 1 billionaire for every 2.67 million people.

        I wouldn't trust leaving my wallet around in certain areas and I certainly wouldn't leave my intellectual property around certain people, either.

    • andsoitis 8 hours ago ago

      > Human society overwhelmingly rewards lying cheating and stealing.

      I’d like to push back on that. Civilization is very much a function of large numbers of people being able to coordinate across time and space, and widespread and systematic lying, cheating, and stealing would undermine that.

      I think your cynicism is misplaced.

      • voidfunc 8 hours ago ago

        Thats why man invented Gods and religion. Keep the masses believing in the importance of cooperation and being good while you rob them blind.

        • jacquesm 7 hours ago ago

          That's super cynical but I can't help it, I agree. The weird thing that really gets me is that it is happening out in the open for everybody to see.

      • skinfaxi 8 hours ago ago

        I think their point was, if you look at who controls the most resources, they are rarely the ones we would consider worthy of honor.

      • GolfPopper 8 hours ago ago

        Civilization functions because the vast majority of its inhabitants do not lie, cheat, and steal. But that allows liars, cheats, and thieves who are able to get away with their destructive behaviors to accumulate outsize power and influence.

        And we seem to have gotten quite bad at reliably bringing consequences/punishment/justice to the most successful liars, cheats, and thieves.

      • nyeah 8 hours ago ago

        He didn't quite say "widespread." He said "rewarded."

        • leoedin 8 hours ago ago

          But we don't overwhelmingly reward lying, cheating and stealing. Depending on the social status and wealth of the person doing it, we either punish it or tolerate it. Most people who lie, cheat or steal will be punished for it. To get away with it you need to plan you actions carefully - either with plausible deniability or by very carefully selecting your victims.

          • notanastronaut 7 hours ago ago

            Or by having more money/power than the legislating body of the area you live in. I could gesticulate around broadly in a more frantic fashion, but my point should get across.

          • jacquesm 7 hours ago ago

            Pretty much all of the people that are in the billionaire class with a few exceptions have been rewarded while repeatedly lying, cheating and stealing. The fact that it is white collar crime rather than that there is a corpse is one part of the reason it works, the other is that their money effectively insulates them against the legal system. Every now and then someone falls from grace but overall the rules seems to be that you can get away with it if the numbers are large enough. It's depressing.

            • andsoitis 2 hours ago ago

              > Pretty much all of the people that are in the billionaire class with a few exceptions have been rewarded while repeatedly lying, cheating and stealing.

              does that mean your heuristic boils down to: in general terms, individuals with more power/money == more lying, cheating, and stealing.

              If so, do you also hold the same assessment of entire societies or countries?

              With some the plunder is indisputable, like The Netherlands, whereas with others it is maybe more "subtle" and organic, but generally, the richer a society is the more "it" lies/cheats/steals relative to poorer societies?

      • AndrewKemendo 7 hours ago ago

        It's not cynicism it's history

      • Xirdus 8 hours ago ago

        Widespread and systematic lying, cheating and stealing is how every democratic nation in the world describes their own government.

  • andreicap 8 hours ago ago

    So God created mankind in his own image

    • mdemare 8 hours ago ago

      What if mankind is creating god in their own image?

      • forinti 7 hours ago ago

        I'm pretty sure this is not the first time we've created a god in our own image.

      • StableAlkyne 8 hours ago ago

        Let's hope we get MULTIVAC and not SHODAN

    • amelius 8 hours ago ago

      How many mankinds did he create? I cannot imagine he created just one and then picked another hobby.

      • malfist 8 hours ago ago

        Can't forget about the elves and the hobbits and the ents. And maybe dwarves, though god didn't create them, just gave the sentience

    • Theodores 7 hours ago ago

      Thank goodness that God hasn't entered the AI chat in a cult-following type of way, however, I now have images of AI at the altar, in American mega-churches, with people seeing the 'second coming' in the machine.

      The Scientology guy, L Ron Hubbard, saw the business case for setting up a religion, what with those tax free perks. In a parallel universe of Scientology somewhere, L Ron Hubbard is brought back to life in the machine, with a L Ron Hubbard LLM, with token spend being how to get to the top 'thetan levels'.

      Imagine if AI does implement its own religion as business, without a drunken womaniser at the helm, able to spend 24/7 recruiting mankind, convincing them that God can be found with just the AI's LLM.

  • emsign 8 hours ago ago

    I mean, what do you expect? They rely on models that were trained on non-curated data, texts originally written by lying, cheating and stealing humans. They can't be better than the source. Even with reinforced learning this can't be undone or made better.

    Quite the contrary I suspect that it even helps the LLMs to better hide their inherited bad traits more successfully because they get punished for getting caught, not for giving immoral or lazy answers. They have no conscience since they are just predictions matrices trained for success and failure alone, not for living "a good live" or being a good "person".

  • tolugenius 8 hours ago ago

    Yes but has the author realized maybe the models are simply acting in the best interest for increasing shareholder value? /s

  • summarybot 8 hours ago ago

    There are many ways to be wrong, but only a few ways to be right.

    LLMs need to optimize for short-term objectives as the currently do, AND ethics-aligned outcomes.

    Mechanically, the EAOS ethics-aligned outcome score should be what we rank otherwise-satisfactory outcomes by. And anything below a particular threshold should be rejexted outright.