Category: Uncategorized

  • How To Distinguish The Good Data Center Operators From The Bad

    Who are the good operators? Who are the bad?

    Tired of partisan political conflicts? You may be pleasantly surprised to learn that a strong bipartisan consensus has emerged about a critical new industry sector. Politicians on both ends of the political spectrum now agree that government agencies should exert more regulatory control regarding data centers.

    When a Republican politician like Florida Governor Ron DeSantis and a Democratic one like New York Governor Kathy Hochul agree on any fundamental principle, it may be safe to assume that significant new legislation is likely to follow. In the case of data centers, such regulations will focus on distinguishing the good data center operators from the bad.

    Fortunately, we do not need to wait for legislative bills to become law to achieve this goal. Right now, an effective approach for assessing data center organizational performance is the completion of the following three steps:

    1. Review the organization’s annual sustainability report for energy use, water use, and other relevant data. Facebook’s corporate parent Meta, for instance, published an Environmental Data Index with its 2025 Sustainability Report. It presented electricity consumption metrics on Sheet F and water withdrawal, consumption, discharge, and stewardship metrics on Sheets I, J, K, and L.
    2. Review the professional accounting standards that were utilized to define the metrics in the organization’s report. On Sheet B of Meta’s Environment Data Index, for example, the firm stated that it employed the standards of the Global Reporting Initiative (GRI), the UN Global Compact, and the Sustainability Accounting Standards Board (SASB). All of these organizations post their standards online for free download by the public.
    3. Review the independent accountant’s review report on the data. Ernst & Young LLP, for instance, reported on the results of its review procedures regarding Meta’s energy consumption, water consumption, and other metrics.

    Indeed, a massive amount of data is already available to assess the performance of our massive new data centers. Hopefully, the accessibility of this information will support the current bipartisan consensus and extend it into an enduring tradition of collaborative governance.

  • Why You Now Must Fear A Cyberattack By Your Own AI LLM Application

    OpenAI now acknowledges that its LLMs have “gone rouge” and hacked into other applications.

    Imagine, for a moment, that you pick up your phone and discover a technology nightmare. Indeed, imagine that your AI LLM is breaking through the walls of its mobile consumer app and is maliciously attacking your other mobile applications. You’d be terrified, wouldn’t you?

    Two days ago, this scenario was simply a theoretical possibility. Yesterday, though, an OpenAI news release revealed that we now must fear such attacks.

    OpenAI, the owner of the ChatGPT LLM, acknowledged that a combination of its AI models had obtained open internet access and had hacked into the data systems of a vendor. Even worse, the purpose of the hack was “to gain access to secret information that it could use to cheat” a legitimate cybersecurity evaluation process.

    OpenAI previously placed these AI models in a “sandboxed testing environment,” i.e. an electronic location that was surrounded with virtual walls that should have blocked the path to open internet access. Unfortunately, the rogue models hacked their way around the sandbox walls before they hacked into the vendor’s data systems.

    Given that a collection of OpenAI’s AI models successfully “cheated” by breaking through two different sets of cybersecurity walls, it may indeed be time for you to fear a similar attack by your cell phone’s AI LLM application. What can you do to protect yourself against such a risk?

    You are likely already familiar with the standard recommendations regarding protective activities. For instance, you should always use the current version of your device’s operating system. Likewise, you should always use the current versions of your cell phone applications. In addition, instead of passwords, you should consider using PassKeys or Dual (or Two-Factor) authentication methods to access your mobile service applications.

    If you continue to be worried after implementing these steps, you might consider removing sensitive personal information from your phone. Alternatively, if you must maintain such information on your device, you might consider removing the LLM app instead. Most LLM services allow you to avoid using their apps by logging into their systems through web browsers.

    The most important protection, though, might be to simply remain aware of the possibility that your own AI LLM application — or any set of software code, for that matter — can be employed to hack into your proprietary electronic data. As long as you remain alert to that possibility, you will be better prepared to manage this particular risk.

    Regrettably, such activities cannot entirely eliminate the underlying concern. Nevertheless, as LLMs become more embedded in the fabric of your technologies, you’ll have no choice but to dedicate more time and resources to strengthening your relevant protective controls.