An Update From the LLM Scaling Laws Frontier | RSAC Virtual 2025
AI models have seen approximately a 4x year-over-year increase in compute for the last 70 years. In the security domain, what has this 4x effective compute brought us in 2025, and what will it bring us in 2026? In this session, Jason will provide a survey of the bleeding edge of security applications from a frontier AI lab perspective, covering advanced persistent threats and the new security challenges AI will introduce—and defend against—in 2026 and beyond.
Transcript
Uh, there's a couple things that we want to talk about today that, that sort of, uh, you know, address some of the, uh, the issues around security that we were talking about in the panel earlier and, and have some overlap with the things that Josh and Matt were talking about. So, I'll touch on all of those, uh, as we, as we go through this presentation. Um, I've been in philanthropic for two years, and, uh, it's been a wild ride.
Um, a lot of things have changed in the last few, uh, last few months even, uh, just, uh, a radical departure, uh, from, from the, the state of the art with regard to especially Uncoding. So we're gonna talk about that today. So, first, before we get started, though, anthropic is a, is a company that, um, has, uh, we are a tech company, but we're also a policy, uh, lab as well.
And so when we think about doing the research on the language models and making sure that things go well for humanity, I mean, we do believe that, um, you know, AI is gonna be one of the most transformative things that's happened since the industrial Revolution. And it's important that those go well. So from a policy perspective, we're engaging with, uh, lawmakers and, uh, decision makers across the, the world to make sure that everyone understands what's coming, um, and we're engaging with the regulatory process and providing insights and education where, where possible.
And that has led to a lot of things that, that are sort of unique to philanthropic. So, I'll touch on those later in the presentation. Um, but, uh, you know, when I think about everything that I'm saying up here, the reason I'm here today and speaking with all of you about, uh, about what's coming is we, we feel like it's, uh, it's really important that everyone in this room has a part to play in making sure that, that that goes well.
So, there's lots of things that I'll call out throughout this presentation that you can keep in mind, uh, as, as these changes come through. So, uh, this is similar to Josh's slide. He just had that slide where he was talking about the, the doubling of, uh, every, every seven months of the task horizon.
Um, this is a graph of the compute power that has gone into, um, um, uh, AI systems or ML systems since, uh, 1957. So that dot, at the lower left hand corner, the most furst left one, um, is, uh, the, the compute power that went into the perceptron in 1957. And this is a logarithmic graph.
7. Um, so the, this is been a massive, massive uplift in the total amount of power, uh, that that occurs. And, you know, we have a trend line here of 70 years, right?
So, um, what do you all think is gonna be the next dot on that graph? Like, do you, I, I personally would not be betting against this graph continuing. It's an important thing to remember that, um, even if, uh, we all were, were trying to slow down or something like that, uh, this, the, the scaling loss hypothesis, which is, which is this observation, the more power, the more data, the more compute that you put into these models, the smarter they get.
Um, and you see the, the seven, uh, month doubling as Josh's graph pointed out, but also the, this line essentially points to a trend of like, basically, um, every, every 12 months, we have a four x increase in the total amount of compute that's going into AI models. So the intelligence will keep increasing, and that will lead to a world where, uh, models, uh, continue to get more intelligent than they are today. So, uh, I'm not gonna talk that much about our product.
I just want you to like, have the contextual understanding. If you haven't heard, uh, of us where we're at. Um, each of the, uh, the Frontier Labs keeps trading blows, um, on releasing new models.
And this is again, uh, a consequence of this scaling loss hypothesis. Claude is, is currently, I think, best in coding. Um, you know, uh, there's other models that have just come out recently that are very powerful and, you know, congrats to those labs, um, Google and, uh, and, uh, OpenAI and, and made all have, uh, exciting releases that have come out in the last few months.
Uh, but we're gonna keep doing this. Like, there's, there's mo new models on the way, on the way all the time, and those models are going to continue to push the, the boundary, especially in coding of what is possible. And I think coding is potentially the place where we see as practitioners, especially the people in this room, are concerned about DevSecOps, um, the most impact.
So, um, everything that I can see from my perspective inside of a lab is the next three years at least, are going to see that continuing, that continuing trend of, of massive model improvement. I don't see an end in sight based on all the research that I'm seeing so far. One of the things that's, uh, really important, uh, for us to, to address though, um, uh, the hallucinations, the jailbreaking, the, the prompt injections that Josh was talking about, Matt, we're talking about all of these things can be addressed by systematically approaching those problems and attempting to address them with scientific, uh, uh, applications.
So, uh, one of the, one of the things that that's really interesting to know about the way these neural, neural networks are grown, that neural networks are grown, they aren't built, you know, we, we, it's almost like raising a child, you know, up through a, through the, uh, reinforcement learning environment. So there's all these reinforcement learning environments that these things are like testing in, and they're growing and they're learning and adapting. And one of the reinforcement learning environments that you can make is just like, be honest, make, make a reinforcement learning environment where you tell the model like, you know, tell me something about, you know, x, x, y, and Z and if it, if it confabulate, if it hallucinates a fact, that's a negative reinforcement in the reinforcement learning environment.
And conversely, you can reward for honest and correct citation of these kinds of things. So there's all kinds of like, really interesting low hanging fruit all across the entire ecosystem of things that we could be doing better that that's, uh, emerging. So, uh, where, where we're at right now is, I think everyone has, I think, internalized now.
Last year I was, I was on stage and I was saying, chatbots are all old, like, we're gonna be doing agents next year. And now I'm on stage and I'm, I'm gonna tell you, agents are old, uh, even though everyone is still, is still adopting them. Um, and the next thing is something that looks much more like a virtual employee.
Um, so we talked about that a bit on the panel this morning. Um, and I'll just repeat the point, um, basically as, um, as degrees of freedom open up in the prompt, like you've got a prompt, a prompt says you are a software engineer and you're doing blah, blah, blah, and you're supposed to be doing the code review. And, um, you know, here's the, the context and everything's in the context window.
Um, you know, if you want to put the highest degree of accuracy on that outcome, you the, like, most obvious thing to do would be to just say, here's the exact problem that I want you to solve for this exact moment. Like, you, you just give it exactly what needs to happen, and you have at least some, uh, guarantee that the right things are in the context window. But as intelligence goes up, like, do we think that way?
No, of course we don't. We, we have everything that we know about our jobs and the business and the software that we're building and our teammates all in our mind and the moment where we're making decisions. And so you can imagine as intelligence goes up and the content of the context window goes up, and especially episodic memory becomes a salient feature, um, memory is like the thing that, I'll talk about this in a second, and we'll unlock this.
Memory is an important aspect of what we see happening in the next year. If you, uh, think about the way that your memory works when you're working in a, in a job function, you're talking to a coworker and your coworker says, blah, blah, blah, blah, blah, you know, um, uh, react, like the word react is dropped in the middle of, uh, whatever technical conversation you're having, right? Um, so imagine, imagine a large language model having the exact same experience.
It's working through a problem, and the word react appears in, in a, in a, uh, change or PR review that it's doing a code review for, um, maybe the change has nothing to do with react, but in the context window and in the way that the model approaches the problem. In the same way that our mind leaps to a bunch of associated and adjacent concepts, and we bring those concepts into our thought process, a model should be able to reach into its broader context and understand the world. So that's where memory and this like contextual flexibility comes from.
Um, and pretty much everybody in the entire field right now is working on memory. So this is gonna be a big feature. So thinking about this going forward is like, I think like, maybe important.
So I won't talk about our, um, product anymore. For the rest side is just going like, what the heck's going on in, uh, large language models is kind of what I'm gonna focus on for the rest of the talk. A lot of what happens right now is, uh, the, the, the world, the world as it exists today is these, these agents, uh, understand the environment by plugging in, uh, concepts.
Um, so model context protocol is getting, getting a lot of legs right now. This is the idea that basically you can have a little server running on your laptop that has like a whole bunch of tools that would, that represent the environment of the, the things that you might want. The one of the, like earliest trivial list examples in that case was the, um, the ability to do web search.
Um, now before, before, um, all of the different ml, uh, ML providers had had their own web search products that competed with perplexity. Um, but there's all these opportunities to just let the model know what, what, what's in the environment, what do I have as options? Here's where I am in this workflow, and, uh, you know, I'm supposed to do A, B, C, D, E, and F, and I'm only on step B.
Um, I try doing C, C didn't work. So I'm gonna see, try and do C prime with a different tool that might solve the problem. I don't have the information that I need to solve C so I'm gonna go use this tool that might have the information that I need.
This is a pattern that can be repeated that makes it possible to take a whole bunch of processes that will be discretized down into something that collapses into, um, one thing that the whole model itself just understands as the, as the current context. You, the downside is you lose, uh, transparency and guardrails by doing this. So there's a constant tension between how much, uh, autonomy and, uh, flexibility do I want to give the model by giving it everything in, in the entire context and the autonomy to choose the next path, uh, and the observability and auditability, um, aspects where you break everything down into discrete steps and you can know what the inputs and the outputs are based on that.
As we, as we think about moving, I was talking about memory, uh, a lot of what's gonna happen over the next year is, is taking everything that I just said about agents and extrapolating that out to the entire problem space of an actual employee's role. So think about, um, like, I think of a couple examples, but like, think about an intern, right? Like an intern joins a company, they have no, no skills, no business skills, yet they require a lot of supervision and handholding to get started.
And I think that as we think about virtual employees, we should be thinking about, uh, you know, an intern coming into your organization who needs a lot of oversight, needs a lot of, um, um, helping to sort of get started. And you think about the level of help that you have to give an intern early in their career, they are getting that, um, that engagement, um, from their manager. Uh, oftentimes that person is the first time manager, which as a pattern, by the way, that I think we should be paying attention to.
Um, uh, you know, they're, they're, they're getting an onboarding, they're getting team docs, maybe a starter project, maybe they're told exactly, I need you to do A, B, C, and D. Those are the kinds of tasks that I think are, are amenable to, uh, the first ver version of virtual employees or virtual collaborators. Um, and the way that it will work is very similar to what I described.
Think about, um, the way that rag systems work. Raise your hand if you know what a rag, uh, system is, uh, in about half of the audience, maybe, maybe three quarters. So a rag system, um, for memory is the same thing, right?
You, you have, uh, fragments of, uh, relevant information that the, that the model has observed in its environment that it thinks might be relevant in the future, that it could encoded in a database and stored in a way that gets pulled into the context window through in vector embeddings that cause, uh, the activation of quote memories, uh, very, very trivial to build now. But, um, like everything else that happens in software, we're probably gonna pay some, you know, software vendor to, to actually do it for us. So this pattern can be repeated and we can see, uh, the, a fairly straight line between where we are now and, and, you know, getting to a place where you can have an intern, uh, level of competency on, on some of these tasks.
It does open up a whole lot of ques security questions, though. So let, let's get to those. I just wanna touch on some of the things that we're doing in anthropic.
They're very similar to the ones that Matt and and Josh talked about at, at, at enro, uh, at, uh, at meda and, and OpenAI. Um, uh, we have a lot of folks who are, um, uh, you know, running through ticket queue. So, so the first thing that I, I'm, I, I've done with our team is like, let people understand that, uh, this is an important moment for them to, uh, upskill, uh, in their career, their career path, and move from just answering tickets all the time to becoming a supervisor of the system that answers the tickets, right?
So this is moving up the career ladder and, and, and, uh, progressing with their skill sets. Um, so we have a lot of those for IT ticket queues, we have those for, um, compliance queues. Uh, automated, uh, compliance questionnaire answering is, is definitely in the, the tasks that are, that are going really well with AI right now.
Um, fully automated security review is maybe one that, uh, some of you should be, should, should maybe look at. Um, if, if you have an application security team that you're working with, um, one of the very, uh, straightforward ways that you can do this today is, um, you take a prompt, uh, and you say, here's the design doc for the system that I'm doing a security review for, and here's the Mitre attack framework. And like, literally go through every single possible MITRE attack framework, um, vulnerability, and look at the, the content of this design doc and tell me, is this thing, uh, going to introduce new vulnerabilities based on everything that we know about our infrastructure and the way that it's connected?
So you can imagine just sort of like giving it infrastructure diagrams and, and things like that. So we have this at anthropic. Uh, I think we're at like 40% of all application security reviews now are fully automated.
Um, where somebody uploads the design doc, uh, it goes through and says, this is a low, low, low risk launch, uh, click the button, and you're, you're, you're approved, you're, you're approved for launch. So this has been a, a huge, uh, productivity boost, supply chain, risk mitigation. Um, there's a couple of vendors in in the market who are trying to, to use large language models to sort of help with the, the supply chain, um, security issue, um, re and, uh, um, so Dev and, and, and others are sort of in this space and, and, uh, and, and, and doing a pretty good job.
We've augmented their offerings with our own, um, uh, interrogation of the, um, like the sig signals that you get. Like, like, let's say for example, you're a security engineer and you're looking at bringing in a third party piece of software. You go to the GitHub page and it's got a bunch of like, AllCat on it, and, uh, it doesn't look, appear to be very serious and largely like only one guy who maintains it.
Um, and his, uh, you know, email addresses, uh, something ru and, uh, you know, all of these, these sort of like soft signals. It's sort of like, uh, I'm not sure sure about this. Um, those all are soft signals that can be interpreted by large language models and feed into a risk score.
So those are, those are quite valuable. Uh, as I mentioned on the panel, uh, automatic code review, which has been a massive productivity win. This is, this has been a surprise for me actually.
Um, so we went through this process of making code review, uh, automated at philanthropic, and the, the, the feedback has been overwhelmingly positive. Um, the reason, uh, it turns out is that folks were like not super happy about waiting for their coworkers to get around to reviewing their code. Um, and now the code review is immediate and the code review is, uh, sufficient for, for landing a pr.
Um, so, uh, just from a productivity perspective, a huge win, uh, and a huge security win at the same time. Like I said, I think we we're not there yet. I I, I think we're probably at, I don't know, uh, 50%, uh, accuracy, uh, of catching, catching bugs.
Um, but, uh, you know, I think human human performance on code review is something like 25%. So it is, it is an uplift in our terms of like getting a security win. And there's like criteria that we apply to win.
We do accept and don't accept, um, automated code review, but this is an opportunity for everyone in this room to experience a massive productivity boost. Um, if, if you just think through the, the application, um, and then, uh, automatic, uh, pen testing too. Uh, if any of you have to engage with outside vendors for the launch and deployment of your products, um, doing that on a continual basis inside your, uh, continuous, uh, continuous delivery pipeline, uh, huge opportunity there with products like Expo and others that are using Claude underneath, um, to sort of drive an automated pin test and automated, um, security assessment in the broad ecosystem, of all the things that I'm worried about, I'm really concerned, and I think there's an opportunity for us as practitioners to have a part to play in vulnerability discovery.
So, um, the AI cyber challenge, uh, has been running for a couple years now, funded by darpa. Uh, there have been a number of, uh, winners in this space that are just, uh, phenomenally compelling. You see, uh, you see, um, there was one, uh, case, uh, last year of an actual a remote code execution vulnerability and, um, in, um, uh, uh, sequel light, uh, that, that was, that was found and proposed and patched, uh, by one of the contestants in the program.
Um, and so, uh, this year is the finalist, the final round, and there's FI seven finalists and, uh, defcon, that will be the, the, the award announced, uh, will be announced. Um, what's happening is, you know, this program started two and a half years ago, and just the model intelligence as, as Josh's slide showed on the project Naptime, uh, which is Google's research as well, um, you just see the model intelligence augmenting the ability to fully automate this process. Um, and it's, it's incredibly impactful.
Um, so when, when I think about code review, when I think about, um, uh, supply chain vulnerabilities and open source software, there's so much, uh, low hanging fruit here that we can just, you know, just apply and get this out there as fast as possible and find and fix the bugs before, um, the nation state attackers and others, uh, get ahold of them. So I think that's super important. And then, uh, everything that, uh, is going on that I just talked about with virtual collaborators is a hundred percent an opportunity for, uh, us, uh, on the security side to be thinking about the right things to do from, uh, from a security perspective.
So, uh, there are so many problems here that haven't been solved yet. So, um, I'll just say there's a, there's a lot, uh, here that needs to be fixed. Um, the first thing, uh, to think about is what exactly, uh, is an agent that's been running for a week?
Is it, is it fully autonomous and accountable for its own actions? I don't think any of us would agree that that's true. Um, you, you asked this thing to do some work for you, it's been running for a week.
At the end of the week, it does something that's not supposed to do. Um, you would think that the person who a, you know, asked the agent to do that work is, is ultimately accountable for, let's say, um, you know, a cybersecurity, uh, incident or something of that, uh, of that case. Those are all questions that still need to be answered.
Um, and in, in the path to getting there, we need to understand the AI went and did, uh, this work, um, and it did it on behalf of this person, and it had these credentials that were provisioned for these, these specific systems that has access to, there's so many problems to solve in here that haven't been solved yet. One of the ways that I've been thinking about this is there's a couple of opportunities to just reuse some old patterns. Um, if any of you have, uh, been in a, been in a CISO like role or been in a, a leadership type role before, one of the things that occurs in this space is that we often have to work with contract, um, companies that are sort of outside of our, our space.
We have contractors come in who we don't necessarily know that well, we don't know that their background is, is compatible with, you know, the company. com or whatever. Um, the reason this is a very useful, uh, security control is when you have separate domain names, um, a whole bunch of DLP type, uh, controls become available and a whole bunch of like, email and Slack and, uh, Microsoft teams controls become available.
Like the, the understanding that there's this idea of data leakage and that there is a boundary between, uh, one domain and another is a really useful tool that we can recycle for things like virtual collaborators and virtual employees. So, as you're thinking about your journey, like one option, one path is I just put everything in system accounts there, everything has an I am role, uh, you know, and, and we're, we're doing a little bit of, uh, confused deputy, um, uh, vulnerability there where, you know, that thing is granted access to lots of things. Maybe it's just in time access, but, um, it looks more like a long running system account and the new world perhaps.
I'm not saying that I think this is a hundred percent true, I think, I think actually maybe there might be some nice middle ground, but perhaps the best answer is actually to provision employee accounts for virtual employees in a separate domain that looks like an untrusted contractor, because you get all of that DLP software because you get those user interface elements that tell you you're about to share outside of your domain in every user context. And then, like, let's say you are, uh, you're on a team and you're in a company and the company has adopted virtual employees, and like literally you had no idea that this had happened. And, you know, one morning you come in, uh, at, at 4:00 AM there's a message from an AI bot that says, hi, my name is Joe, the AI bot, and I'm working on blah, blah, blah, and I'm stuck.
I need help. And I, I found out from the org chart, you're the best person to help me with this. Like, you're gonna get a message.
Not only that, this is an AI bot, you're also gonna see because all of these tools have this like external domain flagging feature in them, that that thing is coming from a different trust boundary. So it gives you the opportunity as a person to make the right decision in that context. Hopefully you're not surprised by these things.
Um, hopefully your company's done good, good communication before these come out. So, but, um, all of this leads to like, where, where is this going? How are we thinking about, uh, doing the right things from a, from a frontier model provider perspective?
So, uh, Matt this morning on the panel mentioned, um, the, the, uh, preparedness framework, uh, anthropic has the responsible scaling policy. This thing lays out, um, based on certain cyber cybersecurity or biosafety, uh, capabilities, what our responsibility is as a model provider to make sure that we are doing the right thing to put the guardrails around enterprise adoption and the way that it gets rolled out into society. So, uh, we are currently at a SL two, which we, we stole the biosafety levels from the biosafety lab, um, regime.
ASL two is, uh, models that are like no dangerous basically than anything that you can get from a Google search. Um, I do think that very shortly we will go to ASL three, which is where models are, um, better able at uplifting bio, uh, bio concerns. Um, those are the kinds of things that you might be concerned about, um, being deployed in your, in your enterprise.
And so tho those are areas to, to keep in mind. But as a model provider, it is our responsibility to block those kinds of harmful things both on the cyber side, but then also, um, a, you know, any of these harms that, that we see emerging. A SL four is the, the one that starts to get really dangerous.
This is a model which, um, given access to, uh, uh, enough, uh, uh, enough compute power and, um, access to the internet could basically, you know, give you the instructions to, to build something of, of grave concern, uh, with regard to, to chemical, biological, radiological, and nuclear risks. So CBRN stuff is in the responsible scaling policy, and then a L five is like a GI, which, or, or something close to a GI. Um, so that, that is, uh, that is all road road mapped out in our responsible scaling policy, and we're tracking, uh, the risk and making sure that we mitigate the risk as we go forward.
So trying to, to make sure that folks understand that this is coming and that we have to put the right safety guardrails in place. Okay, so as we go to ASL four, um, it, I think it's really important that we think about the right, uh, technology at a fundamental level. Um, I showed you that graph earlier, like if there's one thing that I want you to take away from this presentation, it's that graph.
The scaling laws appear to be holding based on everything that I can see at a Frontier Lab. I don't see it slowing down at least for the next three years. I don't know, I can't see beyond the next three years.
And in that world, I need to be planning right now what is the technology that is going to be a, uh, important part of the ASL four story in a couple of years. And so when I've been thinking about that, I think the answer is confidential computing. And, uh, I've been chatting with my counterparts across the industry on this as well, and I do think it's super important.
So at in December, um, at AWS reinvent, uh, with Amazon on stage, we announced a implementation of this, uh, principle to protect model weights and customer data in a confidential computing environment. The reason this is really interesting is, and enables widespread deployment of models that are, like I said, starting to approach that level of concern while still making it virtually impossible for those model weights to be stolen. Um, so this, this is a, this is a diagram.
I'm sorry, it's a bit of an eye chart, but, um, you know, I'm a nerd by at heart, so I I really enjoy the technical details. So, uh, eff effectively what's happening here is, uh, on the model provider side, we take the model weights and we encrypt them and we put them in an escrow. And then in the cloud environment where they're being deployed, it could be AWS, it could be somebody else.
Um, you get an opportunity to take those model weights, um, decrypt them in a hardware envelope that guarantees that it's impossible for anybody to look inside. So, confidential computing does have those, those, uh, those guarantees. The only attack that still works against confident computing, well, one of them is supply chain, obviously, but the other one is like you have to like, have a scanning electron microscope and maybe do some tempest attacks and a bunch of really advanced nation state stuff.
So, super important to get these things in place and be thinking about, um, what the next, next, uh, set of, uh, changes and, and technologies that we need to get out there. So, uh, stay tuned for more. Um, we will also be at the Confidential Computing Summit, um, uh, in a few weeks.
Um, so hope to see you there.