Bruce Schneier on AI: “These massive US AI companies have no viable business model”

Security legend Bruce Schneier has turned his attention to AI, and the future’s not looking pretty. In this exclusive interview with Iain Thomson, he explains why he doesn’t think OpenAI or Anthropic will ever turn a profit

For over 30 years Bruce Schneier has been a leading light in cryptography, security, privacy and internet rights. Now he’s turned his gaze onto AI.

Schneier literally wrote the book on modern crypto – Applied Cryptography – published in 1994 and on curricula around the world. He has devoted his life to sussing out the effects and remedies for security in the modern world – be that in code, privacy, and personal and IoT devices. He’s a board member of the Electronic Frontier Foundation, Access Now and The Tor Project, and now has nearly 20 books to his name.

His most recent book – coauthored with data scientist Nathan E. Sanders – examines the effect of AI on society, security, and politics. Rewiring Democracy: How AI Will Transform Our Politics, Government, and Citizenship is a surprisingly positive take on how AI will influence society, albeit with significant caveats

In this interview, we explore some of the book’s themes and reveal why he believes open source is the right approach.

Let’s start with one of the big questions: Is there a fundamental mismatch between AI guidelines and human rules?

It’s not that the AI doesn’t recognise human guidelines. It’s that it has a looser attachment to them.

What we’re finding is that the AIs are really good at problem-solving, and in a sense, human rules, human norms, human mores are problems to be solved. So, if you give an AI a task, it is more likely to figure out a trick to solve that task.

You know, when I wrote my 2022 book, A Hacker’s Mind, I called this system hacking. Humans are good at this. Humans do this too. The AIs learned it from the training set. The AIs are just better at it, and they do it more frequently.

So does that mean handing everything over to AI and accepting that humans can’t catch up?

There’s no real theory of why an AI does anything that’s robust – we just know that it happens. What’s interesting to me is that AIs have superhuman capabilities to solve these problems, but when it is better than a human, I think of four characteristics: speed, scale, scope and sophistication. 

There are times when you might prefer the AI because it is faster, scale the number of instances it could generate, the scope of its knowledge and sophistication – and I don’t mean smarter. I mean being able to hold more variables in mind.

So, for example, the Double Dutch Irish sandwich. This is the tax loophole that companies like Google and Apple have used to avoid paying US taxes. It involves the US tax code, the Dutch tax code, the Irish tax code and an offshore tax haven – four different jurisdictions. It is a hack. It is a breaking of the rules. It is something that is legal but unexpected.

A human accountant or attorney found that. If you give an AI the world’s tax laws and tell it to find similar things, it probably will. Will it find one that involves a dozen different jurisdictions that’s just simply too complex for humans to notice? Not that we can’t understand the same thing, but that searching for it is too hard. So I think about these AIs breaking rules, and yes, they’re good at it, but I think they’re going to be better at it than humans for those four reasons.

Security is one of your talents. How will AI change this market?

A lot of the AI defences that we’re putting in place are AIs watching AIs. Now, from a theory perspective, this doesn’t work. The AI will always be able to fool the AI. But from a practical perspective, it seems to be quite effective, especially if you use different models.

I think one of the problems we’re having with what we’re calling AI swarms, hundreds of AIs talking to each other. Is it the same AI? It’s not 100 different AIs. It’s 100 instances of the same AI. But if you have different AIs from different companies trained in different ways, watching each other, you do seem to get a square-root effect that is harder for the AIs to get away with cheating. So that’s probably not the answer, but it’s certainly part of the answer.

The two leading nations in AI development are the US and China. How do you see the competition playing out?

These massive US AI companies have no viable business model, and that is because China is producing models that are equally capable and then giving them away. China is using this for geopolitical advantage rather than corporate profits.

So my belief is these open-source models, these smaller models, really are the future. We’re seeing companies cancelling their subscriptions with OpenAI and Anthropic, and downloading an open-weight model, installing it locally, and running it internally because the token costs are astronomical. They’re going to go down, but right now the economics of these big models in the cloud just don’t work.

And remember, when you run a model locally, there can be no guardrails. Any of that stuff that we talk about keeping these models safe fails completely when you’re running it on your own infrastructure. So if you are a bad guy, you’re going to get a lot more value out of these models by running them locally.

So will OpenAI and Anthropic crash? Is the bubble about to burst?

I don’t think there’s any way they can ever make money. There’s no real business model here.

A couple things are going on. One is that the models are basically interchangeable. It’s a race to the bottom. It almost doesn’t matter which one you use of the top three or four. They cost an incredible amount of money to make, and the companies have a few months to recoup that money before another model comes along that’s better.

And then the Chinese are giving away competing models, so it’s very hard to make money when your competition gives stuff away. I just don’t see any way companies like Anthropic and OpenAI will make money. The question is, will the public realise that before or after the IPO?

The thing about any of these bubbles is you kind of know that’s going to happen, but predicting timing is impossible. Wall Street would tell you differently, but they’re full of shit. So we shall see.

Can regulation help make AI safer?

So Europe is reining in AI. We have the EU AI Act. It hasn’t come into force yet, due to pressure from the United States.

We won’t see regulation in the US any time soon. I mean, we were not able to regulate social media, and we’re not going to regulate AI. We need to. This is a global problem. And the AI arms-race framing – which I think is bullshit – also prevents regulation. Just because it means if we’re in a race with China, we’ll do anything possible.

I’m not optimistic about regulation because I just think the US is largely a failed state. I just can’t imagine the US passing a law that pisses off big tech right now.

There’s talk of the US government actually investing in private AI companies. Do you think that’s a good idea?

Certainly the AI companies would love the US to invest because now there’s a huge conflict of interest.

We have a mechanism for taking money from companies that are profitable. It’s called taxation. It’s worked for centuries, worked for millennia. It means we don’t have to pick winners and losers. It means we’re not in bed with the actual companies. So tax them, that is the way to do this, and it’s sort of amazing that we don’t see more of it.

But again, this is the US right now. The money is in charge of what’s going on.

More interviews by Iain Thomson

About The Author

Iain Thomson
Iain Thomson

In over 30 years as a tech journalist, Iain Thomson has worked for PC Magazine, PC Advisor, V3.co.uk, and was a cofounder of IT Pro. In the last 15 years worked for The Register he wrote over 5,000 news, analysis and feature articles for the site, and is also a regular guest and occasional host on The Week in Tech (TWiT) podcast. He is now a freelance tech reporter based in San Francisco.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.