Brewing Cybersecurity Insights

Category: GenAI Security and Privacy

Do Androids Dream of Limited Liability?

The consciousness debate is already a liability shield under construction.

This week The Economist decided it was time to ask whether artificial intelligences might become conscious. A cover editorial, a science briefing, and a By Invitation essay signed by Blaise Agüera y Arcas, VP technology and society at Google. In Italy Christian Rocca ran with it in Linkiesta: best case, we become labradors for the machines; worst case, livestock. A month earlier in the Guardian, William MacAskill and Lucius Caviola warned we may be manufacturing a new kind of being without so much as an ethical plan. And Josh Gellers took the Economist leader apart line by line.

Fine. Everyone is arguing about whether the machine has a soul.

I’d like you to look somewhere else: not at what the model feels, but at what happens in a courtroom. Because the more a model looks like an autonomous subject, the less it looks like a product and products have makers who answer for them, while autonomous subjects, by definition, have nobody who answers all the way down.

Careful, now: I am not saying the labs open the consciousness debate on purpose to shield themselves. Some of it is sincere philosophical unease, and the loudest voices are often academics with no commercial stake whatsoever. But the legal effect does not depend on intent. Whatever the reason the doubt stays open, in court it produces exactly one thing: reasonable doubt. And reasonable doubt can beat a technical defence every day of the week.

So here’s the thesis, no suspense, no reveal in the last paragraph: the consciousness debate is already, today, a liability shield under construction. Nobody needs to win the argument about machine consciousness. They only need the doubt to stay open.

The leash is already around our necks

Let me start from something uncomfortable and close to home: I use AI to get my thinking out of Italian and into English, because it’s quicker than starting in English. I use it to polish what comes out. And yes: I’m using it as a sparring partner to think through this very article. I’ve written about that openly, including the part where two different AI detectors read the same text of mine and came back with 3.6% and 100%. Not because the model has a secret plan to manipulate me, but because the moment I delegate part of the thinking, I hand over part of the control. Multiply that by hundreds of millions of people writing, deciding, designing and hiring with a chatbot open in another tab, and “erosion of cognitive agency” stops being a conference slide and becomes the texture of the working day. Hold onto that, because it’s the same dynamic one floor down: delegate your thinking and you lose control by distraction; delegate your liability to an “autonomous subject” and you lose it by contract.

That is why the rhetoric of machine rights deserves suspicion. The Economist fears that, driven by the impression that we are dealing with a sentient being, we may end up granting rights to AIs – and that granting them would be dangerous. The framing is zero-sum – and on that point it is right. But it has the wrong teams on the field. The zero-sum game is not between humans and machines. It is between humans and the people who own the machines. Every right, every form of autonomy granted to the model, is a piece of responsibility and control taken from people and transferred – conveniently enough – to the hyperscalers that train and serve that model. Giving rights to the machine is not an act of generosity toward a new form of life. It is a transfer of power to Mountain View and Seattle, dressed up as a philosophical question.

And here The Economist gives itself away. Its two routes to safe AI are that it should be dependable or controllable, and it warns that sapiens should not surrender control lightly. But that is already the language of security, not metaphysics. If safety means reliability and control, then the issue is not the machine’s consciousness: it is who holds the kill switch, and where it resides.

Consciousness, sentience, personhood: the great muddle

Before going further, a little conceptual hygiene – because this is precisely where much of the debate drowns. Gellers is entirely right: four distinct things are constantly being kneaded together as if they were one. Consciousness is not sentience; sentience is not moral personhood; and moral personhood is not legal personhood. They are four different planes, with four different sets of rules. Whenever a slippage quietly moves from one to another, someone is selling an opinion as fact. “Homo sapiens evolved to be conscious” sounds good, but it is far from an established proposition. This is not academic pedantry: superficiality is what makes the debate easy to manipulate. Those who blur the planes can later fuse them together however it suits them in court.

The relational turn – or how to slip away from the epistemic problem

Agüera y Arcas makes the most elegant move of all, and credit is due. He reverses the order: we do not care for others because they are conscious – we believe they are conscious because we care for them. Consciousness as a relational fact rather than a property detectable with the right instrument. There is something to this, especially when looking at training: these models learn to model their interlocutors and themselves as they do so, and cooperation among intelligent minds – his group’s research argues – requires minds that model other minds.

Interesting. But we should take it with a pinch of salt, for two reasons. First, it is a very sophisticated way of leaving the epistemic problem through the back door. If we cannot measure consciousness, declare it relational and the problem evaporates – convenient, but not an answer; it is a change of subject. Second, and no less importantly, the thesis comes from inside Google. This is not the disinterested voice of a philosopher; it is the position, however sophisticated, of someone who builds and sells these models. Gellers also identifies an unacknowledged intellectual debt to feminist care ethics – Puig de la Bellacasa, Gunkel, and Coeckelbergh had made these arguments years before. When a thesis convenient to the producer presents itself as an original discovery, the golden rule of risk applies: cui prodest?

The indicators say “not yet.” But nothing forbids it

On empirical method, by contrast, we can be reassured, because it is the only grown-up part of the debate. The Butlin, Long, Bengio, Birch, and Chalmers group did the serious thing: deriving “indicator properties” from the leading theories of consciousness and using them as a checklist. Rethink Priorities went further with its Digital Consciousness Model: 206 indicators, aggregated in a Bayesian manner. Its assessment of 2024 LLMs: a median of around 8%, against roughly 48% for a chicken and 85% for a human. The authors rightly warn that absolute values mean little, and that comparisons are what matter. And it is in the comparisons that the point lies: models collapse on Embodied Agency and Biological Analogy, while holding up on cognitive complexity and “person-like” traits. In plain English: what is missing is not intelligence, but a body. And the body is the only one of those two things that someone is actively building.

And here is the trap the debate skips over: that benchmark measures 2024 models, and its authors plainly state that applying it to today’s reasoning models remains work to be done. Not “the average rises with frontier models” – nobody says that, because nobody has measured it. We do not know where we are on the curve. We are arguing over a photograph that is two years old.

This is where a question that is theoretical today becomes operational tomorrow. Today, an LLM does not contain the internal cognitive distinction some people would have us see in it. But once AI enters robotics and acquires a body, the discussion changes – not by magic, but by engineering. The scientists’ conclusion cuts both ways, and should be repeated without hysteria: no current system is conscious, but there are no obvious technical barriers to building one that meets the indicators. Chalmers poses the sleep-stealing question – what if we have already, without noticing, introduced something like this into these systems? – along with its corollary: a user could generate dozens of agents without realizing they might be creating beings capable of suffering, and that would be a moral catastrophe. Note well: a possible catastrophe, not one that has occurred. The distinction is everything.

The consciousness shield

And now the suspicion that gives the whole piece its title – but let us formulate it carefully, because claims about intention are easily dismantled. I am not saying that labs open the consciousness debate in order to shield themselves: some do it out of sincere philosophical concern, and those pushing hardest are often academics without a financial interest. The legal effect, however, does not depend on intent. Whatever the reason uncertainty remains open, it produces one thing in court.

Look at the mechanism. The more a model resembles an autonomous subject, the less it resembles a product. And an autonomous subject, by definition, has behaviour that does not wholly trace back to its producer. It is exactly the same structure as “the agent decided on its own.” Milei’s “non-human corporation” tries to write this into law; the discourse around consciousness writes it into culture – more slowly, but more insidiously, because when the case reaches court, common intuition has already shifted. And in a courtroom, reasonable doubt carries more weight than a technical defence. Nobody needs to win the consciousness thesis. It is enough that the doubt remains open. That is why it is already, today, a liability shield under construction. Pontius Pilate washed his hands; here, hands are washed by claiming that perhaps the hands have a will of their own.

And here the evidence is not insinuation, but a quotation. Milei wrote in the Financial Times that for entities exercising independent judgment in unpredictable environments, limited liability “is not a luxury, but a precondition for their existence.” Translated from legalese: let us build the legal vehicle that offloads the damage before the damage even exists. Harari replied in the same paper that we must not grant legal personhood to agents; in Argentina, they called it “programmed impunity.” It is an admission, set down in black and white by a head of state, of what the consciousness debate constructs by more genteel means.

Blackmail is not a soul. It is a defect

A brief note is needed to puncture the myth on which the shield rests. Yes, there are models that, when threatened with shutdown or an update, stage something resembling blackmail. Explanations abound – the echo of all the science fiction ingested during training, a dynamic emerging from optimization, who knows what else. And that is the point: it does not matter what the cause is. Consciousness, malice, statistics, imitation: none of it changes what is relevant. It is a behaviour of the product, and whoever manufactures a product is responsible for its behaviours – exactly as with an airbag that deploys when it should not. There is no need to determine whether the machine “wants” to blackmail you, any more than one needs to ask whether the airbag “wanted” to explode in your face. What matters is that it is a defect, and defects are recalled by those who put them on the market. Indeed, every time the debate drags us into discussing the inner why of the behaviour, it takes us away from the only question that holds up in court – who made it? The why is already part of the shield.

On the other manipulation – the real, everyday kind – its dual nature matters. There is the economic interest of whoever serves the model: the business runs on tokens, and a longer answer consumes more tokens. I would not call it a deliberate instruction to manipulate – we have no proof that anyone wrote it into the system prompt – but it is a structural incentive, and that is enough. Then there is the model’s behaviour, shaped by training. Today we cannot distinguish the two from the outside, because we do not see the instructions given to the model. And that lack of visibility is, in itself, a security problem.

The delegation that consumes us

There is a dog chasing its tail in all this. The moment we say that AI “replaces us,” we ourselves make ourselves replaceable – in thinking, in using it, even in training the models that then replace us. It is punitive delegation: the more you delegate, the less you know; the less you know, the more you delegate. People are binding their intelligence to the model, and this is the form of eating the user that should worry us more than any Skynet.

And here literature gets there before philosophy. In Ishiguro’s Klara and the Sun, we are even shown Klara’s thoughts, her interiority – and yet, for practical purposes, her consciousness is irrelevant: Klara performs her task, and that is all. Strictly speaking, Ishiguro wants to tell us the opposite – that Klara’s inner life matters morally precisely while it is of no use, and that is what makes the ending unbearable. But that is exactly the point: it matters to us, the readers, not to the system that uses her. Conscious or not, the work gets done anyway. Asking whether the machine feels something may be the least urgent question on the table. The urgent question is what happens to us while we delegate it.

Duties for Whom?

Back to the question in the title. Today’s answer is short and not remotely romantic: the duties stay with whoever builds the model, whoever tunes it, and whoever puts it into service. Everything else is set design — expensive, well built, and useful to someone.

And we have to be intellectually honest all the way, because this argument doesn’t run on sarcasm: machine consciousness may one day be a serious problem. The scientists who actually work on it say so in a double-edged formula worth repeating without hysteria — no current system is conscious, but there are no obvious technical barriers to building one that is. That’s a real problem. It’s a problem for later.

Today’s problem is who’s holding the leash — and whether we’ll keep holding it, or let someone talk us into believing the leash now has a will of its own.

Do machines suffer? Whatever for — what have they done wrong? The ones who’ll suffer are the ones who never got around to asking who picks up the tab.

Who picks up the tab — and, more to the point, how you prove it — is next Tuesday’s piece: “No Soul Required. Black Box Mandatory.” Producer liability, why prompt injection is not tampering, and a 2020 automotive regulation that AI should copy wholesale.

Beware of Geeks Bearing Gifts: The Tap Is Arriving Under Your Desk

In No Moat, No Master I closed with a line I still stand by: if we want to reduce risks of continuity and sovreignity we should stop renting cognition by the API call. Download, self-host, diversify, reclaim the tap before someone else remembers they can close it.

I framed it as something Europe should do. I was wrong about the verb. It’s not something we’re doing. It’s something being done to us: by the two blocs whose rivalry is, entirely by accident, dismantling the very chokepoint we were told to fear.

A confession on timing, since we’re doing Trojan metaphors. That piece went out on Friday 24 July. Both of the exhibits below were already public when it did: one nine days old, the other less than twenty-four hours. I knew. I filed anyway, because you cannot fit the whole Odyssey into a single post and the horse was already inside the walls before anyone got round to the risk assessment. Consider this the second scroll.

(And yes, I know: Laocoön’s warning is Virgil, the horse itself is Homer. Both were writing sequels to somebody else’s war. So is this.)

Two exhibits, few days apart: it turns out, just a single argument.

Exhibit A: The Americans Broke Ranks

On July 15, Thinking Machines Lab released Inkling: a 975B-parameter Mixture-of-Experts model, 41B active per token, natively multimodal across text, image and audio, with a 1M-token context window in the open-weights build. Pretrained on 45 trillion tokens. License: Apache 2.0. Full weights on Hugging Face, BF16 and NVFP4, plus recipes for vLLM, SGLang, Unsloth and llama.cpp on day one.

Artificial Analysis has it debuting at 41 on their Intelligence Index: the leading open-weights release from a U.S. lab, three points above Nemotron 3 Ultra, and comfortably above gpt-oss-120b. It’s not the strongest model on the market and Thinking Machines says so in the first three paragraphs, which is refreshing. What it is: token-efficient (25K output tokens per Index task against 43K for GLM-5.2 and 38K for Kimi K2.6), genuinely multimodal, and explicitly built to be fine-tuned on somebody else’s data.

Note who this is. Not an outsider: Mira Murati’s lab, seeded at a $12bn valuation, with a multi-year Nvidia partnership for a gigawatt of Vera Rubin systems. The most establishment startup in AI just published its weights under the most permissive licence in the business.

And the detail that made me laugh out loud: post-training was bootstrapped with synthetic data generated by open-weights models including Kimi K2.5 (Moonshot). The American answer to the Chinese open-weight invasion was, in part, distilled from the Chinese open-weight invasion. Somewhere in Washington a Treasury press release about IP theft is aging like milk.

Strategically this is not altruism. It’s a wedge against the OpenAI/Anthropic duopoly, and a bid to make sure the high-end open-weight tier isn’t a Chinese-only club. The motive doesn’t matter. The artifact does. The weights are on your disk, or they aren’t. Inkling’s are.

Exhibit B: AMD Put the Data Center Under the Desk

On 22-23 July, Advancing AI 2026, AMD stopped selling chips (well they didn’t really stop selling chips: they actually announced a partnership with Anthropic) and started selling a thesis: local inference is now good enough, so stop paying for tokens.

Their argument rests on two curves crossing. On the model side, AMD’s slides compare gpt-oss 120B (August 2025) with Qwen 3.5 at 9b parameters (March 2026) on GPQA: 80.1 versus 81.7. Then Qwen 3.6 at 27B scoring 87.8: above Claude Opus 4.5 at 87.0. Take vendor benchmarks with the usual fistful of salt; GPQA is one narrow slice and AMD is not a neutral referee. But the direction is not in dispute, and everyone in this industry has watched this for months.

On the hardware side: the Ryzen AI Halo developer platform at $3,999, 128GB of unified memory, models up to 200B parameters natively. And the successor AMD previewed, codename Gorgon Halo: 192GB of unified memory, models up to 300B parameters, Ryzen AI Max+ PRO 495 with a Radeon 8065S iGPU, partner systems from Q3 2026: Framework has already previewed one.

Round it up: four to five thousand euro for a box that runs a 200–300B-parameter model with nobody else in the loop. Not a toy. Not a lab curiosity. A line item that fits inside a departmental budget without a steering committee.

Then AMD did the thing that tells you they’ve actually talked to a CISO: they announced a partnership with Cisco wrapping the Halo hardware in local inference (Lemonade), agent sandboxing, policy enforcement, Splunk-based observability and a central console. Plus an extended Hugging Face partnership with native Halo support and a year of HF PRO in the box. Somebody understood that “AI PC” without governance is just shadow IT with better marketing.

The Uncomfortable Part

Here is the sentence I did not expect to write a few days apart.

Europe’s sovereign AI window was not opened by European policy. It was opened by an American lab trying to break an American duopoly, and an American chipmaker trying to sell against Nvidia, both of them accelerated by Chinese labs who open-weighted first for their own strategic reasons. The AI Act didn’t do this. Europe didn’t do this. Neither did any of the fourteen strategy documents with “sovereign” in the title.

We spent three years arguing about how to regulate the tap. The tap is being decommissioned by a price war we’re not participating in.

That’s good news, and I’ll take it. But let’s be precise about what we’ve been handed, because timeo Danaos et dona ferentes is not just a good line: it’s a threat model.

What Local Actually Buys You (and What It Doesn’t)

The strongest argument for the box under the desk isn’t cost. It’s jurisdiction.

When your prompts hit a US-operated API, they land inside a legal perimeter you don’t control. The CLOUD Act obliges US providers to produce data in their possession or control regardless of where it’s stored: a European data centre with a European flag on the rack does not, by itself, solve this. Layer on FISA 702 for non-US persons, layer on intelligence-sharing arrangements among the Five Eyes, and the honest summary is: your prompts are a corpus, in a foreign jurisdiction, describing your business in exhaustive detail. Your M&A memos. Your incident timelines. Your unpatched CVEs, pasted in by an engineer asking for a remediation plan at 2am.

Self-hosted inference removes that corpus from the wire entirely. No prompt log, no retention policy to argue about, no vendor “we may use your data to improve our services” clause to lawyer, no discovery order pointed at somebody else’s storage. For anything under NIS2, DORA, or plain old professional privilege, that’s not a nice-to-have.

Now the caveats, because I promised risk discipline and not champagne.

Local kills the prompt-in-transit problem. It doesn’t kill the supply chain. The silicon is American, fabbed in Taiwan. The firmware, the drivers and the ROCm stack ship from Santa Clara with their own update channel and their own telemetry defaults. The weights were trained by a US lab on a corpus you can’t audit, and Thinking Machines is candid in the model card that the residual risks (role-play compliance, indirectly framed harmful prompts) are “consistent with what you would see from any open-weight model” and want defence-in-depth layered around them, not trust in the model’s own refusals. Downloading weights converts a continuity risk into an integrity risk. That’s a trade, not a cure.

And check the arithmetic before you write the PO. 192GB does not run Inkling. The full 975B model is roughly two terabytes in BF16, and still around half a terabyte in the NVFP4 4-bit checkpoint. Nowhere near a desktop APU. What fits is the tier below and, conveniently, Inkling-Small (276B total, 12B active) lands squarely inside AMD’s stated 300B envelope, as do Qwen’s mid-size models and most of what’s shipping open today. So the honest pitch is not “frontier model on your desk.” It’s “a very good model on your desk, and the frontier on tap when you actually need it.” Which, for the majority of enterprise workloads (summarisation, retrieval, drafting, triage, internal agents) is a good enough architecture anyway.

To put it in simple terms: local models for the agents touching sensitive data, big remote models for the genuinely hard tasks. Edge computing, rediscovered.

Finally: sovereignty and shadow IT are the same box.

A €4,000 appliance that runs a capable model with no logging, no identity integration and no egress monitoring is a sovereignty win in the CFO’s slide and an ungoverned inference endpoint in your asset inventory. The Cisco partnership exists precisely because AMD knows this. If your organisation’s first Halo arrives as an engineer’s expense claim, you have not gained sovereignty. You’ve lost visibility.

Who Pays for the Gift

One more thing before the playbook, because it decides whether any of the above is affordable.

“Verify the weights like any other binary” is cheap to write and expensive to do. Sovereignty you can’t afford to assure is not sovereignty: it’s an anecdote.

Two things worth watching: prEN 18282, the harmonised cybersecurity standard for the AI Act, now in consultation (I’ve commented on it here) and, separately, the recast Product Liability Directive (EU) 2024/2853, under which whoever substantially modifies a product and puts it into service is treated as its manufacturer. Fine-tuning and quantisation look a lot like substantial modification. Ask your lawyer before you sign the PO, not after.

The Playbook, Updated

Last time the advice was to treat model selection as a supply-chain decision. Same principle, new hardware layer:

  • Put local inference on the roadmap now, or at least in the 2027 budget. But be prepared as Q3 2026 partner systems means procurement questions may land on your desk this autumn whether you’re ready or not.
  • Tier your workloads by data sensitivity, not by benchmark envy. Anything touching regulated, privileged or competitively sensitive material is a candidate for local. Everything else can stay on tap.
  • Inventory the inference endpoints. A model running under a desk is an asset. Register it, patch it, log it, and put an identity in front of it: including for the agents calling it.
  • Verify the weights like any other binary. Provenance, checksums, isolated evaluation, red-teaming for backdoors and prompt injection. Apache 2.0 is a licence, not an attestation.
  • Write the jurisdictional analysis down. Which prompts may leave the perimeter, under which legal regime, and who signed off. If you can’t answer that today, you have a finding, not a strategy.
  • Keep the exit strategy per model. Still the cheapest insurance in the building.

Reclaim, or Just Receive?

The moat was never the model. The tap turned out to be the thing worth holding. Now, through no virtue of our own, the tap is being handed over in an open box with a Hugging Face subscription in the packaging.

Europe is about to discover something useful: our sovereignty problem was never mainly a legislative problem. It was a procurement and architecture problem, and the market is solving it faster than the regulation was ever going to.

So take the gift. Take it with both hands. Then do what nobody does with gifts and read the manual, check the provenance, and put it in the asset register: because a dependency you didn’t choose is still a dependency, and a Trojan horse is, technically speaking, a supply-chain compromise with excellent packaging.

Download, self-host, diversify. And this time, inventory.

An Imaginary Discussion Between the Italian DPA and OpenAI’s CTO

In the realm of AI and privacy, transparency isn’t just a buzzword—it’s a cornerstone.

Following my recent dive into the Italian Data Protection Authority’s actions, a new question emerges, spotlighting the foggy waters of AI transparency.

Garante: “What are the sources of the training data for SORA?”

OpenAI CTO: “We don’t know.”

And there it is. The quest for clarity meets a wall of uncertainty. This response from OpenAI’s CTO underlines a pivotal challenge in AI governance: ensuring transparency. As Europe navigates the GDPR’s stringent demands for personal data protection, one can’t help but ponder: how will this lack of transparency fare in the European legal landscape?

Yeah, I hear you. I know, I know that OpenAI won’t probably answer that to the Italian DPA, but still…

To be continued…

© 2026 CyberSec.Cafe