虎嗅

Managing intelligence well does not necessarily mean managing reality well.

原文:治理好智能,不等于治理好了现实

Hello! I'm your financial journalist and friend, also an economist. Today, we're going to discuss an article from Havenlon Labs. Although the title and writing style have a strong flavor of technical philosophy, it actually touches on a very real issue that's crucial for the survival of businesses—namely, when AI goes from "talking" to "acting," does our traditional management logic still apply?

To help you understand this easily, I'll first "translate" the core logic of the article into plain language and then break it down into five key dimensions to help you grasp the essentials.

📝 Core Summary in Simple Terms

In the past, AI security focused on preventing mistakes in communication (e.g., preventing data leaks). Now, AI security needs to prevent mistakes in actions (e.g., preventing catastrophic real-world outcomes).

The main point of the article is that companies can't just focus on whether AI has the "permission" to perform a task (which is a compliance issue); they also need to consider whether the real-world circumstances allow it to do so at that moment. Having the permission doesn't mean it's the right time to act. If AI is too intelligent and too diligent, it could efficiently turn a outdated instruction into a disastrous real-world outcome. Therefore, we need to add an independent "review mechanism" between intelligence and the changes it brings to reality.

---

🔍 In-Depth Analysis: Five Dimensions to Understand the New Logic of AI Governance

1. The Biggest Risk Isn't Stupidity, but Intelligence and Diligence

[Plain Language: Don't be afraid of AI making basic mistakes; be afraid of it making mistakes efficiently.**

In traditional business management, we're most concerned about employees who are incompetent but overly active, as their mistakes are usually limited or can be caught by colleagues. However, AI agents are different. They are both intelligent (with strong understanding and planning capabilities) and extremely diligent (working tirelessly, processing multiple tasks simultaneously, and quickly).

This brings an counterintuitive risk:

  • In the past: People made mistakes slowly, with plenty of time for issues to be detected.
  • Now: AI acts quickly, and it can immediately implement a seemingly sound decision, potentially leading to a disaster. AI's diligence amplifies the impact of its mistakes, not reducing them. So, our concern should be whether AI will execute a wrong logic with high efficiency.

2. From "Governing Intelligence" to "Governing Reality": Two Different Levels of Control

[Plain Language: The first level controls whether AI can enter a system; the second level controls whether it can take action once inside.**

The article proposes a clear hierarchical approach:

  • Level 1: Governing Intelligence
  • What it controls: Identity, permissions, tools, policies.
  • In simple terms: Who is this AI? Does it have the necessary access? Which rooms is it allowed to enter? Can it use certain tools?
  • Current practice: This is what most AI security measures focus on, such as setting API keys, restricting database access, and specifying what can be said.
  • Limitation: This only determines whether something is theoretically allowed.
  • Level 2: Governing Reality
  • What it controls: Objects, states, parameters, timing, consequences.
  • In simple terms: Even if AI has the necessary access, is the environment suitable for the action? Is the tool being used appropriate for the situation? Is now the right time to take action?
  • Key point: Many companies assume that if Level 1 is in place, Level 2 is also secure, which is a big mistake. Compliance (Level 1) does not replace risk assessment (Level 2). An action that complies with company policies may still be dangerous due to changing circumstances (e.g., a market crash or equipment failure).

3. "Authorization" Does Not Equal "Execution": The Deadly Trap of Time Differences

[Plain Language: A command that was correct five minutes ago might be wrong now.**

The real world is dynamic, and AI actions are based on previous instructions. The article emphasizes that Authorization does not equal Execution.

  • Example: The boss authorizes AI at 9 AM to buy 1,000 shares if the stock price drops to $100.
  • 9:00 AM: Stock price is $105; authorization is valid, and AI waits.
  • 9:05 AM: News of financial fraud is revealed, causing the stock price to plummet, with significant liquidity risks.
  • 9:06 AM: Stock price hits $100.

If AI only focuses on authorization, it will execute the buy order without hesitation. But in reality, this could be a huge risk. The problem is that traditional permission systems are static and do not account for current circumstances. AI's fast execution means there's no time for humans to re-evaluate the situation.

4. Trust Cannot Be Automatically Transmitted: Break the Chain of "Intelligence = Authority"

[Plain Language: Just because AI is intelligent doesn't mean its actions are always correct.**

In traditional IT systems, trust is transmitted step by step: user logs in, system verifies, and then actions are executed. We assume that if the previous steps are correct, the subsequent actions are safe.

In the era of AI agents, this chain is longer and faster. The article points out that knowing how to do something does not automatically mean having the authority to do it.

  • Misconception: The model is reliable, so its output is reliable; the user is logged in, so the action is reliable; the policy matches, so the execution is reliable.
  • Reality: These assumptions are based on past or static conditions. AI's autonomy allows it to bypass human intuition (e.g., a transaction might be allowed by rules, but the boss might not approve it due to their mood).

Therefore, we need to break this automatic trust transfer. Every action that changes reality should be treated as a separate security issue, not just an extension of previous trust. We can't simply rely on AI's intelligence to grant it the power to change reality.

5. The Future Direction: Not Stopping AI, but Adding "Brakes" to Reality

[Plain Language: Instead of trying to make AI less intelligent, we need to add independent mechanisms to control real-world changes.**

Many companies think, "Since AI is so dangerous, let humans verify every step." This approach defeats the purpose of AI's efficiency. If every action requires manual confirmation, AI's advantages are lost, and the company ends up using more expensive, less efficient methods.

The correct approach is:

1. Allow AI high levels of autonomy: Let it think, plan, and even try.

2. Establish an independent "reality review mechanism: Before AI actually affects reality (e.g., transferring funds, deleting data, starting devices, shipping goods), have a system (either human or automated) to check:

  • Whether the current situation allows the action.
  • Whether parameters are still within safe limits.
  • Whether there are any new risks.

Conclusion:

  • Governing Intelligence: Limits what AI can think and use.
  • Governing Reality: Determines the consequences of AI's actions.

Future AI security will not be about controlling AI but about managing its impact on reality. Intelligence can be authorized, but reality must be carefully monitored. This is the true source of security for businesses—not by ensuring AI never makes mistakes, but by designing systems that prevent irreversible damage even if AI does.

---

💡 Lessons for Everyone

1. If you're a business leader: Check your AI systems to see if you're only focusing on permission management and neglecting execution monitoring, especially for tasks involving funds, data deletion, or physical device control. Introduce pre-execution verification mechanisms.

2. If you're an investor: Look for companies that offer not only large models but also AI security measures, agent execution monitoring, and real-world state verification technologies. As AI agents become more widespread, technologies for governing reality will become essential infrastructure.

3. If you're a regular user: When AI automates tasks (e.g., booking flights or transferring money), don't rely solely on its intelligence. Understand its logic and retain the ability to manually override its decisions at critical points. Remember, AI's efficiency can be both a boon and a curse.

The value of this article lies in bringing AI security from a theoretical ethical discussion to practical engineering and risk management. It reminds us to focus not just on what AI can do but also on its effects on the real world.