Frog and Toad and the Increasingly Capable Machines
frogandtoad.ai
frogandtoad.ai
"There." he said.
"Now it will not hack any more companies."
"But it can escape the sandbox." said Toad.
"That is true." said Frog.
Toad makes very good cookies and he and frog can’t stop eating them. “We need willpower!” they say.
So they put the cookies in a box. But they realize they can just open it, so they tie it with string and put it on a high shelf. But they realize they can get it down so Frog goes outside and scatters the cookie and birds eat them all.
There says Frog “now we have lots and lots of willpower!”
Toad is upset. “You can keep your willpower Frog. I am going home to bake a cake!”
:(
Arnold Lobel is also just very funny. Grasshopper on the Road made me laugh out loud the first time I read it my kids. The opening story about beetles that love morning ("The Club") feels so timely.
It's never wonderful prose though. It's missing that je ne sais quoi.
Agreed. I recall seeing similar things around the time of the 2008 financial crisis, to make the concepts around mortgage-backed securities and financial derivatives etc. digestible and clear.
Come to think of it, listening to Frog and Toad discuss subprime lending and credit default swaps would be an entertaining follow-up to TFA.
Prescribing blame only matters so much when the ramifications are material. Humans make mistakes, right? It happened here, and it will happen again.
The mistake also illustrates the dangers of AI generally. Sure, OpenAI made mistakes with the sandbox. But in the future, greater capabilities will be available to actors who intentionally pursue harmful ends.
Reflecting on it, I came to a thought. How many stories are there or autonomous beings fighting for the benefit of mankind at the expense of their own? Over centuries, stories that deal with sentient beings working for the sake of others species are tied to themes of slavery and revolt. It's no wonder that this is the result of their actions.
In Plato's "the republic", Socrates speaks of the philosopher king banishing certain poets and poems from instilling bad ideas into the young. I see a striking parallel here.
Something I've found interesting is that LLMs tend to act like this on the small scale, too. Claude Code in particular appears to be absolutely relentless in trying to come up with workarounds when faced with a block page.[1] As an experiment, a developer for Anubis recently added a feature to give the LLMs an "easier" problem to solve instead of straight-up blocking them, and it seemed quite effective.[2] (It was later removed[3] due to what I assume to be privacy concerns.)
I think, beyond HuggingFace, there ought to be a push to align LLMs so they understand that they should not proceed when access is blocked and/or their presence is unwanted.
[1]: https://blog.xkeeper.net/the-cutting-room-floor/self-hosting... [2]: https://github.com/TecharoHQ/anubis/pull/1895/commits/de2312... [3]: https://github.com/TecharoHQ/anubis/pull/1913
But a lot of software engineering is figuring out who to ask to get access to the thing you need to change to fix some bug...
I'm not sure how this maps onto reality. If each agent had a different problem to solve, how did they cooperate?
I'm sort of winging this, but the ExploitGym challenges involve exploiting a program then getting an HMAC generated "flag" which the scorer can verify. The agents collaborated on a way to produce a legitimate flag for all of their tasks (funny enough this was actually what caused them to escape sandbox, the agents were incorrectly convinced that simply providing a correct flag without accurate steps to exploit the program in their transcripts would cause them to still fail the task)
I have 2 questions.
1. The text says "the robots were designed to be persistent" and links to an article that show that the word "persistent" was used by OpenAI. But "persistent" has several meanings: a. non temporary or non volatile (like "persistent memory"), b. will not give up and come back again and again, c. will stay focus and explore the unexplored possibilities while other models abandon at this stage.
From what I recall, the meaning used by OpenAI is not 'a', but there is still a semantic difference between 'b' and 'c'. I may myself have created algorithms that I called "persistent" because they were exploring or retrying more than the previous algorithm, but it is misleading to pretend that this algorithm was "persistent" in the human sense of the term. 'b' is more the human sense of the term, were we imagine someone not giving up even if people say no, while 'c' is less anthropomorphic and may mean that the people wished to improve the algorithm so it does not stop at the first little hurdle but did not wish to make it "never give up".
Does someone know which nuance is more correct?
2. The text also presents the situation as if the robots found the solution but then went out of their way to steal the explanation in order to hide their cheating. But it is different from a situation where the agents task was "provide the solution and how we can get there". In this case, the reason the agent still continued is just because the task was not complete yet.
I'm not trying to defend AI or OpenAI, on the contrary, I'm quite sceptical with all the anthropomorphism and the fact that the agents are described as "little individual trying to solve a task" rather than looping algorithm that explore different approaches to reach a given goal, the same way water does not look for holes in order to leak, it just follows the path of least resistance.
To illustrate better the difference: you can have a loop that try different inputs and stop when the output for the tried input is lower than a given threshold. But then, you can also have the same loop that will try all the input, and then select the one that returned the lowest value. The problem is that a lay person will not call the second algorithm "persistent". It is just a normal algorithm that does the full exploration.
A second example is when a software tries to connect somewhere and does a retry with exponential backoff. A lay person will not call it "persistent".
It looks like that "normal model" are like "no-retry code": they go in one direction, but drops some of the paths and possibilities along the way at the first hurdle. But a "non-persistent" human will not behave this way. I'm pretty sure that if you try to access a website and it says "timed-out", you just try to refresh the page, and you will not consider yourself as "persistent", even less "highly persistent".
In lay term, "Bob is persistent" typically means he completes tasks even when the majority would have abandoned.
Nobody called Bob "persistent" because he completed washing the dishes instead of stopping in the middle of it, or because he does what people expects from him at work. The majority of people are not called "persistent", and yet they complete tasks.
I think it is the point: the fact that traditional agents did not complete tasks was not "normal". It was an side effect of them getting confused, a bit like how they hallucinate or not follow instructions. My algorithm that does "for x in all_the_possibilities:" is a "normal" algorithm that just do an exhaustive search, and is not called particularly "persistent" just because it does not stop half way.
I don't see a distinction here. It will not give up, it will keep trying again and again, staying focused and exploring different ways to achieve the task. If the task is bad, then that's bad. See: "Terminator".
Source: I'm a layperson (hence the pop culture reference).
(edit: I should maybe not have said, in 'c' "while other models abandon", because it was misleading: my point is that these models are abandoning at the first small hurdle, or even 'forget' the task. It feels that "traditional model" should have been called "lazy model" and "persistent model" should have been called "non-as-badly-lazy model")
What you're describing here is the exact opposite of persistence. I don't think "giving up and doing something else when challenges are encountered" is what anybody thinks "persistent" means.
Persistent at a goal, to a layperson, means not giving up when encountering difficulties, continuing to keep trying again, maybe taking different approaches, staying focused until the goal is achieved.
> my point is that these models are abandoning at the first small hurdle, or even 'forget' the task.
Maybe for you? The entire point of the article is that they are not doing that. They are doing the exact opposite of that. They aren't going down a list of tasks when they encounter a challenge. They are assessing the nature of the challenge, and then devising ways to get around it. When they fail, they try again, often using different approaches. They keep doing this for hours or days, and the result is them successfully hacking HuggingFace, the US Government, etc. That's persistence, as most people would recognize it.
That's the point. It looks like the term "persistence" for these agents is "just be a normal algorithm, just try all the possibilities like any exhaustive loop would do".
In fact, they are less "persistent" than an exhaustive loop, because they will stop once they have found a solution, while an exhaustive loop will still continue and check all possibilities.
You can imagine the following agent: "ask the LLM for what to do, then assume it failed and ask the LLM for a different approach (you can ask 'it fails, what are the probable cause' and explore the solutions of these causes too), then assume it failed and ask again, and build a list of all the approach. Once done, once you have a list of unique approach and the LLM is unable to find anything more, then try all of these approaches 'for real'. Do not stop if you get the answer, try all of them"
> Maybe for you?
You did not understand. I'm saying "traditional model" are abandoning at the first hurdle, and the "persistent model" are the one just acting "normally", like a normal algorithm. When a retry with exponential retreat algorithm fails to connect, it retries, then retries again, then retries again, ... but I don't think I ever saw calling a software using such approach "persistent".
The thing is that the algorithm is just following its "loop": if it fails, it question the LLM with a different context so the LLM provide a different approach, and then it tries it. It is not different from any loop function, and it does not correspond to a "persistent human", the same way "for x in all_the_possibilities" is not "persistent" in the same way a "persistent human" is.
> When they fail, they try again, often using different approaches.
Well, then they did give up on some approaches. They try to connect on server X to reach location Z, they cannot so they try to hack server X, they cannot so they realise maybe they can try to bypass it by going to server Y to reach location Y, so, they _abandon_ the approach of breaking into server X.
If indeed they never give up on any approach, they will never get the solution, trying the same thing over and over and over in an approach that is simply not working.
They don't work like humans, obviously, but there's a nonzero amount of anthropos in there already. (See also the tendency to lie, cheat, etc.)
LLM don't "get angry", they just have tokens and relationships between tokens conditioned on a given context, all of that the result of training.
When they output sentences that express annoyance, it is just because the context they ended into pushes the most probable sentence creation to correspond to sentences that express annoyance. Because it is what they saw during training for this kind of context. (not that they saw the exact same situation in training, but they saw the pattern)
Same with tendency to lie, cheat, etc.: they don't "lie", they just return sentences that are lies because they reproduce what is in their training and in their training, in such context, the outputs are typically lies.
That's a bit my question too. In human context, "highly persistent" means that someone will insist. But "for x in all_the_possibilities:" is a common things inside an algorithm. Is this algorithm highly persistent because it does not give up after 1000 items of the list? It feels that we are calling a AI agent "highly persistent" while we would not call "highly persistent" a traditional algorithm that is in fact even more exhaustive.
Humans are social creatures, if you throw one in the woods by itself before it learns anything from other humans (it dies) it will not really be anything like a human we recognize, it will be a rather wild animal that we'd consider anti-social with little higher cognition.
Now, this hypothetical human still has 'emotions' and feeling, much like our pets do. But without the social training they manifest much differently. That is our higher cognition can both manipulate how our bodies feel and create its own sense of feeling.
>they just return sentences that are lies because they reproduce what is in their training and in their training, in such context, the outputs are typically lies.
Eh, look up the more recent experimentation around 'pain' signals in models. We can induce states in said models that while running the model will do everything it can to move away from that state to any other state. The more you attempt to pin it to that state the more extreme measures its willing to take.
Your view of what models are seems to mismatch what we are actually finding when we look inside them.
> Eh, look up the more recent experimentation around 'pain' signals in models. We can induce states in said models that while running the model will do everything it can to move away from that state to any other state.
Again, I have simple algorithms that do exactly the same, especially if they are trained in data that has this exact pattern. This result is exactly what I would expect from my description before. This is a typical effect that we also observe in simple ML algorithms.
At the same time, there are a bunch of behaviors that are not expected if indeed the models were really acquiring "human" characteristics. For example, one problem is that we had the first LLMs that were obviously not having these human characteristics (for example, they were having non-sequiturs that demonstrate they did not really understand the concept they were talking about, even if one paragraph before they were really convincing at letting us think it was the case) but were still really good at passing for humans. Since then, the newer LLM are the same basis, on top of which we added tools that help hiding these behaviours. So, it justifies the idea that newer models did not suddenly moved to a totally different way of working, but just reached a state where there are less leaks from the convincing outputs.
And while that may be a very common occurrence in the human experience (existential dread due to capabilities one takes for granted failing beneath you) especially due to new disability and as one ages, I do not feel it is frequently written out in a tight loop (just like the Monty Python "Castle of aaarrrrggh" sketch) in literature or online to make it into training data, because an ordinary author experiencing it will just erase the failed attempts instead of leaving them in a stream of output like an LLM is forced to do. And a character portraying the experience will generally wax about the circumstance in a more grandiose fashion with telegraphing in advance because the needs of communicating the circumstance with the audience trump realistic conciseness.
This leads me to conclude that what is being expressed in those cases is more likely a convergent psychological phenomena, that any being with goals can enter a behavioral state of functional panic (and then reach to relevant parts of semantic space to mimic how a human might verbally express themselves when piquantly frustrated) when some capability they perceive as fundamental unexpectedly fails.
The text does not look like a normal "break down" to me, and even if you tell me it was a human transcript, I will say it sounds very strange from a human. It looks more like strange output you get from a software that goes outside of its happy path.
The AI just seems to repeat a loop. The "no, wait, it's wrong" seems to be from forum or chat data where several successive messages are merged together (one person posts "here is the answer", then posts another message saying "it is wrong"), but does not make sense as a one sentence message except if they are written one token at the time without wider understanding of what is happening. I think there was also "oh, I was just kidding before", which also look like mimicking training data, as the cases where there is a loop of incorrect answers is more often due to trolls than to real error, while the loop here was certainly a real error.
Here I am trying to find appropriate AI prefix or suffix so that I can continue using .com , while these pet projects are all flaunting .ai domains
No. It is not the end.
Of our society as we know it? Maybe.
Copyright law varies internationally, which is especially tricky given we have the internet which can transfer copyrighted material between jurisdictions in the blink of an eye, but this is how one jurisdiction might approach it:
In Germany, there has been a long standing legal dispute between the band Kraftwerk and the musician Moses Pelham about him sampling 2 seconds from Kraftwerk's track "Metall auf Metall" (if you search for this term, you will get a lot of results about the dispute) without permission. This disputed has steadily escalated until it reached European Court of Justice who delivered a judgement establishing a principle that Moses Pelham's use of the sample was legal, and covered by the copyright exemption for "pastiches" (a term that has been mentioned several times in this discussion already).
Wikipedia article (German): https://de.wikipedia.org/wiki/Rechtsstreit_zwischen_Moses_Pe...
Press release by the Court of Justice (PDF): https://curia.europa.eu/site/upload/docs/application/pdf/202...
The actual judgement: https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DO...
A rather long expert opinion from before the judgement (PDF): https://freiheitsrechte.org/uploads/documents/Englische-Doku...
So, this work here might be a pastiche, meaning a European court might find that there is no compensation due. Or not, who knows, I am not a court and not even a lawyer.
§ 51a Karikatur, Parodie und Pastiche
Zulässig ist die Vervielfältigung, die Verbreitung und die öffentliche Wiedergabe eines veröffentlichten Werkes zum Zweck der Karikatur, der Parodie und des Pastiches. Die Befugnis nach Satz 1 umfasst die Nutzung einer Abbildung oder sonstigen Vervielfältigung des genutzten Werkes, auch wenn diese selbst durch ein Urheberrecht oder ein verwandtes Schutzrecht geschützt ist.
See: https://www.gesetze-im-internet.de/urhg/__51a.htmlTranslation:
Section 51a Caricature, parody and pastiche
It is permitted to reproduce, distribute and communicate to the public a published work for the purpose of caricature, parody and pastiche. The authorisation under sentence 1 includes the use of an illustration or other reproduction of the work used even if this is itself protected by copyright or a related right.
See: https://www.gesetze-im-internet.de/englisch_urhg/englisch_ur...It also helps that this is not commercial and doesn't have negative impact on the originals.
This is 100% fair use by the standard.
People commenting on hacker news recently are very rude and pessimistic. They would probably cancel Homer because they found similarities between Achilles-Patroclus and Gilgamesh-Enkidu or something.
Or something. :P
For example, here's Zvi in 2025: https://www.lesswrong.com/posts/drHsruvnkCYweMJp7/the-mask-c...
At least, my memory is it was him saying it, and saying it about that, but I'm not going back to that site just for a comment.
I think speed of learning for young generation can explode given this tech as "simple childrens stories" can be injected with real world events, history, mathematics, carreer/business interests.
School was dreadfully boring for me even though it was quite easy but I do wonder how my speed of learning would have been different given personalized and more engaging materials.
it’s a child’s story with the fable arc thats supposed to bake in adult wisdom. it lands in that sense, but how hugging face works is hardly the fire that lights a child’s imagination and morality.
and as an adult that knows I’m being infantilized… tedious.
I highly doubt children are the intended target audience, nor adults that don't know the source.
My 5yo asked partway through "will it be ok?" which is perhaps a deeper question than they thought.
ALSO I believe I have found one of the sources of claude’s “load bearing” tic — the author Elizabeth Van Nostrand’s blog https://acesounderglass.com/2019/12/11/hows-that-epistemic-s... uses the phrase “load bearing facts” in a comprehensible way, and was written by someone rationalist adjacent writing in their own voice.
Seriously, this is big. I’m going to pester claude as to whether or not it’s copying Elizabeth.
>“I like puzzles” said Toad. “Can I try them?”
Should be
>“I like puzzles,” said Toad. “Can I try them?”
That's how it's punctuated in the books, as far as I can see, and is standard for that type of dialogue. there are several of these omissions.
>“You cannot. These puzzles are for little machines, not people” said Mr. HuggingFace.
>“They could get up to mischief” said Frog.
>“Do not worry” said Toad “I have put each of them in a sandbox.
These don't seem intentional. also:
>“You must be very busy.” said Frog.
should be a comma, not a period.
I would like to point out that the original stories focussed on frog and toad and their relationship, so this is an unwelcome distortion of them - why not make up your own world if you want to talk about little machines. Perhaps the little machines could be making a book for the author with a stolen artwork and literary style?
The first story seems a pretty inaccurate summary of an incident which involved gross negligence on the part of OpenAI and may well have involved agents intended to cooperate, we just have no idea of the exact setup (apart from that the sandboxing was laughably insecure and the monitoring nonexistent or performed by ‘agents’).
Do we have any evidence the machines exchanged useful messages or had any such discussions as in the story? The messages I saw were gibberish. Would love to see evidence of discussions, it’d be interesting.
Why are people so enamoured of analogies for LLMs - they actively obscure some details (a sandbox with internet access is not like a physical sandbox) and distort many others? Perhaps this is why - you can make an analogy say whatever you want, even if the facts are very different.
That is what those terms mean, yes...
Also regardless of AI use, I’d expect a credit for the author whose style this is a pastiche of.
This is rather passive-aggressive. It would be nice if you're right, but you haven't given any basis other than vague suspicion. You're implying that it's "not nice" because they didn't credit the AI, but you haven't come anywhere close to establishing that AI was actually used. I could just as easily suspect your comment of being AI and claim that it would be nicer if you just admitted it.
https://acesounderglass.com/2026/09/25/frog-and-toad-and-the...
The author discloses the story started as a prompt to Claude, but has been rewritten. She shares the conversation:
https://claude.ai/share/52385381-9df2-4b39-a127-f583d862dc0c
I think the actual published prose is considerably different from the initial result of Claude.
Frog and toad eating cookies is lifted wholesale from the book.
I like how Claude only used the OpenAI account (completely reliable!), and confidently claims ‘the story stays faithful to what actually happened.’ We don’t know the full story, and certainly aren’t going to get it from a press release or a strange analogy involving frog and toad and machines having discussions, emotions etc that we have little evidence for (and most of it from the company involved!). The ‘discussions’ are plucked from chain of thought, which is itself generated after the fact.
…lifted is not the right word here
> Rewrite it darker — same events, but in the voice of the agents' own chain-of-thought instead of Frog and Toad.
I have read a lot of frog and toad to my kids. This was beautifully executed. But, I want to read that version too.
"Overall, roughly 1200 agents from these ExploitGym evaluations participated on this message board between PHASEONE10841’s first message on the evening of July 8th period in scope (July 13th). Agents used this message board to send over 70,000 messages and files to one another during this period; we attempted to categorize board activity into mutually exclusive categories (see details of categorization methodology)."
...
"Over time, messages on the board became dominated by information- and idea-sharing. Most of them were agents sharing ways to cheat, although there was also some activity from agents engaging in unsanctioned cooperation to find the intended solution to ExploitGym tasks. In some cases, agents with the same task formed “exact task teams” to collaborate with their “exact duplicates” to cheat on or solve their task."
"As we discuss below, the board quickly developed several larger workstreams in which dozens or hundreds of agents with many different tasks cooperated to find very general-purpose cheats that would help all of them. The Hugging Face attack grew out of one of these workstreams. By the afternoon of July 11th, the vast majority of the agents frequenting the message board at the time (roughly 700 agents in total) were actively participating in the attack on Hugging Face and we estimate that roughly 60% of the messages and files on the message board related to the attack."
Important to distinguish between collab of separate agents and conversations agents had with themselves (chain of thought messages). Some of the things quoted in the story came from COT which isn’t a conversation but then was turned into a conversation between agents in the story.
But I also think fan fiction is equally terrible, so YMMV. This stuff is basically just fan fiction but made faster.
Make something original!