LLMs are black boxes that are no different than any other software black box. If anything, they are *less* trustworthy as third parties because they have a large, unexplored attack surface. > (1) being able to audit their processing LLMs do not provide this as a benefit to any greater degree than any other software, and often times are *much* less able to do that kind of introspection. That's why they "hallucinate" so much. They do not think; they are *not* AI. > (2) being able to delete it and erase their knowledge when their work is done Again, so can any other software system. It's just non-scientific hype that doesn't seek to disprove the claims of the fake-AI industry. > But we can easily imagine more complicated questions that cryptography can’t solve. “Which of these two novel manuscripts has more sex scenes?” “Which of these two business plans is a riskier investment?” I'm sure you understand that those are not in any way cryptographic questions. The evaluation of what is a sex scene or what is a risk is *entirely independent* of how that information is exchanged between parties. > If Alice and Bob can agree on an AI model they both trust Neither should be putting their trust into a software system they don't control. > And it’s reasonable for Alice and Bob to trust a model with questions like this. They can take the model into their own lab and test it a gazillion times until they are satisfied that it is fair, accurate, or whatever other properties they want. That's nuts. It is not at all "reasonable" to assume there are no backdoors just because you tested the LLM model. You'd have to audit the source that *built* the model, and then you'd have to audit the supply chain that *deploys and runs* the model. Again, the use of AI adds nothing here to increase the system's trustworthiness. > The paper contains several examples where an AI TTP provides real value. I very much disagree! It rather seems to present some extremely worrisome scenarios. "Allow landlords to constantly record everything tenants do in their apartments and give all those videos to us on the off chance one day our system will say YES to a property damage query"? Not interested, Google. > This is still mostly science fiction today It should stay science fiction. What these companies are trying to do makes the kind of dystopian surveilence done in _1984_ look downright minor. 0f3fcd0459c3336eb75edb44f09daf076af65b00bb80fe3c161a74c41d527a74