You don't know what your model is going to do when you tell it what to do.
Give a model permission to act on your computer and you're trusting it will behave the way you expect. It might not.
In this clip from our Braintrust conversation, Adam Berman, engineering leader at Semgrep, breaks down why a backdoored model is a different threat model than backdoored software. You can't fuzz-test your way to finding it, and you often can't detect it until it's already acting the way it shouldn't.
Full episode out Thursday.
Braintrust is Cortex's community for engineering leaders working through what AI is actually doing to their teams, their systems, and their risk. More at braintrust.cortex.io.