
September 3, 2026
9/3/2026 | 55m 36sVideo has Closed Captions
Jeremy Diamond; John Manley; Heidy Khlaaf
Jeremy Diamond reports from inside the Lebanese Army. Former Canadian Deputy Prime Minister John Manley discusses ongoing tensions between the U.S. and Canada. We take a look back at conversations with the late women's rights activist Gloria Steinem. Heidy Khlaaf, Chief AI Scientist at the AI Now Institute, brings clarity to the OpenAI "Hugging Face" hack.
Problems playing video? | Closed Captioning Feedback
Problems playing video? | Closed Captioning Feedback

September 3, 2026
9/3/2026 | 55m 36sVideo has Closed Captions
Jeremy Diamond reports from inside the Lebanese Army. Former Canadian Deputy Prime Minister John Manley discusses ongoing tensions between the U.S. and Canada. We take a look back at conversations with the late women's rights activist Gloria Steinem. Heidy Khlaaf, Chief AI Scientist at the AI Now Institute, brings clarity to the OpenAI "Hugging Face" hack.
Problems playing video? | Closed Captioning Feedback
Where to Watch Amanpour and Company
Amanpour and Company is available to stream on pbs.org and the PBS app.

Watch Amanpour and Company on PBS
PBS and WNET, in collaboration with CNN, launched Amanpour and Company in September 2018. The series features wide-ranging, in-depth conversations with global thought leaders and cultural influencers on issues impacting the world each day, from politics, business, technology and arts, to science and sports.Providing Support for PBS.org
Learn Moreabout PBS online sponsorshipHello everyone, welcome to Amanpour and Company.
Here's what's coming up.
This from Israel.
America.
Scarred by war, a country in ruins.
A rare look inside Israeli occupied Southern Lebanon.
Then.
Canada has taken advantage of us.
They have ripped us off for years and now we're turning the tables very, very easily turning the tables.
When the Americans stop doing memes, stop throwing shade, stop trying to be tough, and start being serious about having those discussions, we can have those discussions.
Once great allies locked in a trade dispute and a war of words.
Can this be rectified?
I asked Canada's former Deputy Prime Minister John Manley.
Plus... The people who say the fight is over are the same people who used to say to me it's impossible.
You know, it's against nature.
And now their current form of obstructionism is it's over.
No, no, no.
We've just barely begun.
Remembering the remarkable Gloria Steinem and her relentless fight for women's equality.
And... I've never seen any of these companies or these AI safety labs propose nuclear level regulations.
AI safety fears solutions with safety and security expert Dr.
Heidi Klaf.
Amanpour & Company is made possible by The Anderson Family Endowment Jim Atwood and Leslie Williams Candice King Weir The Sylvia A. and Simon B. Poita Programming Endowment to Fight Anti-Semitism The Strauss Family Foundation The Peter G. Peterson and Joan Gantz Cooney Fund Charles Rosenblum Monique Schoen-Warsaw Kou and Patricia Ewan Committed to bridging cultural differences in our communities.
Barbara Hope Zuckerberg And by contributions to your PBS station from viewers like you.
Thank you.
- Welcome to the program everyone.
I'm Christiane Amanpour in London.
Flattened homes, raised villages, shattered lives.
The situation inside Southern Lebanon still occupied by Israel.
The Lebanese army is now seeking to regain control from both Israel and Hezbollah.
I spoke to Lebanon's president Joseph Aoun in June.
This was his message to Israel then.
Are you really want to live in a perpetual war?
Aren't you fed up with war since 1948?
Do you want really to live in peace?
Let's sit and talk.
For the Israeli government, it's the time for the power of reason to prevail over the reason of power.
Military activities or military solution will never provide you with security and safety to the northern people.
He said they're ready to sit and talk.
Awoun also called for talks with Hezbollah.
Well, now, correspondent Jeremy Diamond has exclusive and rare access to southern Lebanon, embedding with the Lebanese army.
And he takes us into that war zone.
From this coastal road to the rubble-strewn countryside, you'd be forgiven for thinking this is Israeli territory.
But it's not.
This is a rare first-hand look at occupied We're currently driving through Israeli-occupied southern Lebanon.
In fact, we just passed an Israeli military checkpoint.
We're in a convoy of vehicles, dozens of families reaching their homes inside the Israeli zone of control, three Christian villages where many people are still living.
The only way in or out of this area for these families.
Israel invaded this area nearly six months ago after Hezbollah, the Iranian-backed militant group that is based here, fired rockets at Israel for the first time since 2024, retaliating for Israeli strikes on Iran.
We're really close to the Israeli border now and this is all we're seeing, piles of rubble, one home after the other, completely destroyed.
A ceasefire is technically in effect here, yet Israel carries out near daily strikes.
Most of this rubble was caused not by airstrikes, but by bulldozers and controlled demolitions, part of Israel's plan to raze every town and village in this area, with only a few exceptions.
A trio of Christian villages have been spared the fate of their Shia Muslim neighbors.
The contrast really is quite striking.
We're now inside one of those Christian villages, and as you can see, there is life here.
But below the surface, life is far from normal.
The residents here are surrounded by the ruins of neighboring villages.
So where is Bintish Be'el?
And the sights and sounds of war.
Even two-year-old Joe recognizes the sounds of jets overhead.
What's in the sky?
Airplanes.
Planes, jets.
Like many in this Christian village, Yorgos blames Hezbollah, which embedded in the surrounding Shia villages, for bringing war to his doorstep.
It's from our side, sure.
What do you mean by our side?
Why we did all of this?
And you can see the results.
When you see their destroyed homes, what do you think?
Do you feel like they deserve this?
Do you feel like... No, no, no.
Nobody deserves like this.
Nobody.
Sure, no.
We can't live alone.
We need to all together.
We need our government to be here and to take responsibilities.
The Lebanese government says it's now trying to do just that, deploying the army to reclaim sovereignty over southern Lebanon from both Israel and Hezbollah, a task it's trying to accomplish without coming into conflict with either one.
We need to work to see that we are working in a very dangerous situation and a very harsh situation.
That danger comes into focus as soon as this soldier begins telling the story of the Israeli strike that killed his comrade.
The soldier who died was standing with us at this point and I was next to him.
He was shot in the head and died immediately.
When you were first deployed to the south... And that was some kind of Israeli strike close by.
Despite the ceasefire, Israel has struck the next town over.
So this is at least the fourth Israeli artillery strike that we have heard in this area since we've been here and we've only been here for about 20 minutes.
How often are you seeing Israeli military strikes like this?
It's continuous in all the area of operation.
As I told you since the 27th of June framework agreement, we had no more than 5,000 attacks.
So it's continuous and it's everywhere in all the sector of the responsibility.
This is what is what's happening.
This is from their side.
The Leb soldiers have been killed died in Israeli strikes.
ordinance.
In the fifth seven soldiers died durin is a very risky and dange As part of the ceasefire agreement with Israel, Lebanon is working to clear the south of weapons held by non-state actors like Hezbollah.
This fiber-optic drone is just one example.
Rockets, missiles, drones, missiles, heavy artillery, small grenades, IEDs.
We are finding munitions deployed by the Israeli enemy forces and we are finding munitions dropped by armed groups from Lebanon.
The scale of the challenge comes into view as we drive through the south, a bastion of Hezbollah support where the group's flags and martyrs posters line the roads, before arriving in the town of Zawtar al-Gharbiya.
This is a pilot zone, under the US-backed framework agreement between Lebanon and Israel.
Until recently, behind Israel's yellow line, the Lebanese army is meant to keep armed militants out.
Soldiers now patrol the town, man checkpoints at its entrances, and monitor military activity from observation posts like this one.
This is really quite striking.
You have a Lebanese Army observation post right here, and just a few hundred meters away on the opposite hilltop, an Israeli military position.
The pilot zone means some families have been able to return to their homes, or whatever is left of them.
Here, anger at Israel and the United States for backing it is still raw.
People from Israel and America.
And peace is impossible to imagine.
We were killed.
Our country was killed.
Our loved ones were killed.
Our friends were killed.
Our homes were destroyed.
How can they think that one day they will be able to live in peace?
I was five months away from my country.
We left.
We left the country.
I was hoping that the people would come and help us.
I was hoping that they would come and help us.
I waited for 10 minutes, 15 minutes and they came.
I could smell the soil.
This is my land.
It loves me.
It loves me and I love it.
I won't leave it.
It won't accept that I leave it.
Darwish barely flinches at the sound of the nearby airstrike.
It is here, amid displays of defiance, that Lebanon is probing one potential path forward.
Here where Israeli airstrikes still ring out, and where Israeli tanks and Hezbollah flags can still be seen.
"The ultimate objective, the final objective is clear.
It's the Lebanese state authority inside the pilot zone, strictly."
"But why is the Lebanese army not going and kicking in doors and confiscating weapons?"
"That thing needs the full deployment of the army.
That needs the full recovery of the south.
And that thing needs also the ceasefire from the Israeli side.
And doing things in violence against our own people, it will be also with other sequences.
Lebanon is a country with a history of civil war.
Is that one of the reasons why, you know, the Lebanese army is not being aggressive against Hezbollah because you want to avoid another civil war?
I'm saying that we will do this slowly.
We will do this in a reasonable way.
Is it fair to say though that one of the Lebanese army's central tasks is to do all of this in a way that avoids the potential for a civil war?
For sure, that is something from the pillar of the thinking of the army.
Who will fight the children of his country?
But in the same time, we are not going to accept something illegal.
And Jeremy is joining me now from Tel Aviv.
Jeremy, it's incredible to see that access there.
There's a couple of questions I want to ask you, but first, obviously, the big question is, can the Lebanese state impose its sovereignty and its authority there to keep both sides together?
I know that's what you were asking the official, the officer you were talking to.
Did you get the impression that the Lebanese army is in control?
No, I would not say that they are in control in particular because there is still this huge swath of the country that remains under Israeli occupation.
You know, there's no question that the Lebanese army has the willingness and the desire to take back Lebanon's sovereignty, you know, to get the weapons from armed groups like Hezbollah, to take back territory that the Israeli government is currently occupying.
And the Lebanese government is really at this inflection point where we have heard, as we did in your interview with President Aoun, you know, this rare, never-before-seen willingness to say enough is enough with these paramilitary groups in our country, we're going to take back control.
But doing it is another matter entirely.
Their task is complicated not only by the fact that Israel is continuing to strike on a daily basis, but also because Hezbollah is not a party to this ceasefire agreement and certainly has not agreed to relinquish its weapons.
And then beyond that, you know, these pilot zones are so, so small right now, Christian, and they don't even include areas that have been fully occupied by the Israeli military.
These are areas where Israeli troops went in perhaps at some point or were bombing.
I did, off camera, from a lot of these soldiers and other officials I spoke to, heard a lot of pessimism about the future of these pilot zones and whether or not they will really be able to lead to the kind of Israeli withdrawal that so many Lebanese want to see.
They certainly do want to see it.
Now you're back in Israel.
You remember, and we all reported it when the Israeli defense minister threatened to raze every house in that area near the border.
And we know that Netanyahu is not disposed to really doing the negotiating work.
It's still all war all the time.
So what are you hearing now in Israel since you've come back?
Well, we haven't seen any indication from the Israeli government that they're willing to expand these pilot zones to withdraw Israeli troops.
In fact, the Israeli prime minister and his defense minister, as they are now in full election campaign mode with those elections slated for late October, are making quite clear that they are not going to withdraw Israeli troops from Lebanon anytime soon, and certainly not before those Israeli elections.
Now, we did see the Israeli prime minister sit down earlier this week with the US ambassador to Lebanon, Michel Issa, who has been involved in these Israel-Lebanon negotiations.
So clearly there are still conversations that are happening, but we have not seen many concrete measures to actually push this forward towards some kind of a real resolution.
And look, we've seen you obviously reporting amazingly from the West Bank as well.
What is the situation there, given the fact that Israel has also taken a huge and heavy hammer to that place?
Well, there's no question that the Israeli security establishment seems to be kind of waking up to the reality of settler violence in the West Bank, that they are concerned about a potentially major casualty incident that could result as we're seeing this violence continue to escalate.
But we are still seeing that in many ways their hands are tied and that Israeli soldiers on the ground are continuing to support and back up these settlers in so many instances.
Just yesterday, we saw two people were shot by Israeli soldiers who had accompanied a group of settlers to take back, according to them, sheep that they said had been stolen by the Palestinians.
Palestinians on the ground say that it was the other way around, that these, you know, that Israeli settlers have been stealing their sheep on the ground.
And so right now it just seems like we're at a moment where the campaign season is influencing what's happening in the West Bank more than anything else.
Israeli settlers, right-wing members of the Israeli government trying to kind of solidify so many of the facts on the ground that we've seen them establish.
And despite the fact that the security establishment seems more willing to counter some of this violence, they certainly don't have the tools to do it in the way that they need to.
And we're still not seeing the Israeli police under the far right minister, Itamar Ben-Gvir, actually going and arresting settlers en masse in the way that you would expect with any kind of serious crime and violence problem.
- Yeah, Jeremy Dimon, thank you so much as ever.
Donald Trump is once again attacking Canada.
Listen to the latest.
I have China coming here.
A lot of people say, "Who's the toughest one to deal with?
Is it China, sir?
Is it China?
Is it Vietnam?"
I said, "No, actually it's Canada."
Canada has felt emboldened.
They had presidents that didn't know what was happening.
Not only the last one, all of them.
I mean, they just were taken into... Our country's been taken advantage of by Canada.
>> This bad blood between allies shows no sign of abating right now.
Prime Minister Mark Carney continues to stand firm after the collapse of trade talks last month.
He's preparing retaliatory tariffs as we speak.
So, let's bring in John Manley, Canada's former Deputy Prime Minister, Finance Minister, and Minister of Foreign Affairs.
He's joining me from Rideau Lakes in Canada.
Welcome to the program.
You have had basically portfolios that cover the gamut of all the national security, foreign policy and economic policy of your country.
When President Trump says that you're being unreasonable and taking advantage of them, and now with Prime Minister Carney not blinking, would you, I guess, are you pro that or do you think there's a lot of risk to be concerned about?
- Well, of course, there's a lot of risk.
The United States is a much bigger economy.
We're not interested.
I don't think Canadians are interested in having any kind of heated dispute, trade or otherwise with the United States.
However, I think it's important to put this in context.
We have a, we're not looking for an agreement with the United States.
We have an agreement with the United States.
It was signed in 2020 by Donald Trump.
It was declared the best agreement ever, trade agreement ever by him at the time, and he has unilaterally breached it.
So it's not surprising that Prime Minister Carney is pushing back.
Now, President Trump, in that clip we played, brought up the only two countries that in fact stood up to the tariff regime and to various other economic threats from the Trump administration, China and Canada.
And China, though, has massive leverage in that it has crucial mineral wealth and rare earths.
What do you think you have to take this same stance?
In other words, what is the bet that China, sorry, that Canada can hold out and essentially stand up for itself in this war of tariffs and war of words?
Well, first of all, we have a lot of things that the United States does need.
It's notable that none of these tariffs, including the ones that were added at the last minute, you know, based on legislation from the 1930s applied to energy, to electricity, to potash.
These are things that the United States continues to bring in duty free from Canada.
And basically, when you go back and analyze the numbers before all this started, they are the reason that Canada had a small trade surplus with the United States.
If you look at manufacturing and services, the United States actually had a surplus with Canada.
So I think it's bizarre and illusionary that Canada has nothing the United States requires.
The President keeps saying this, but of course it's simply not true.
Now after the trade talks collapsed, the Prime Minister, Prime Minister Carney, stated his rationale for going head-to-head.
And as I said in the introduction to you, he is right now, as we speak, the government is planning their tariffs, which are going to be rolled up, their counter-tariffs, which are going to be rolled out, you know, just in a few days, on Tuesday, I believe.
This is what the Prime Minister has said.
Take a listen.
Last spring I warned that America is trying to break us so they can own us.
And I promise that that will never ever happen.
We are keeping that promise.
Canada is becoming stronger and less dependent on America.
We are already giving ourselves more than they can take away, and we are just getting started.
So if we're just getting started, per the Prime Minister, where do you think this is going to lead, Mr.
Mani?
Doesn't your country have to really, really, I guess, toe a very, very tricky line between standing up for itself, as the Prime Minister says, and not, you know, kind of enticing or enabling any further attacks from the United States?
Well, I think we have to worry about them continuing to increase the pressure.
I mean, these last tariffs came on in the midst of a negotiation going on, some of them as high as 50% on commodities crossing the border.
But of course, if every time the US adds tariffs, we give them some concession, that's no way to get to an agreement.
So I think there was really they left us with no choice but to push back.
But I think Prime Minister Carney's laid out a pretty clear game plan.
I mean, it's first it's to try to defend the North American relationship.
We would like the United States to honor its agreements, sign them in ink rather than in pencil, as he said, so that we can count on them.
Secondly, to aggressively diversify, try to get to build our relationships with other markets.
We already have comprehensive trade agreements, both with Europe and with many of the Asian countries through the CPTPP.
So we have a network of very promising and strong trading relationships.
And thirdly, to make Canada itself more competitive.
I mean, we can't blame Donald Trump for the fact that we've had some vulnerability.
He didn't create our low productivity performance and so on.
We've relied on the integrated market.
And now we're going to have to realize that while that's an asset, it also can be a vulnerability and we're going to have to do better on our own.
Canada was a very prosperous G7 country before the first trade agreement was ever signed with the United States.
We can be that again.
I'm interested that the Prime Minister is going to Europe, to the European Parliament, I think he's going to be meeting with the head of the EU.
And I guess he's going to talk to them about what they can all do together.
We remember so famously back at the beginning of this year, where in Davos, he talked about a rupture, not a transition, between all countries' relationships with the United States, not just Canada's, and the need to figure out, and you've laid out some of the plan.
Europe has famously tried to do its own sort of deal, mitigating it.
In other words, trying to get less tariffs rather than hitting back.
What do you think the Prime Minister can expect to hear from Europe?
What will he tell them?
- Well, I think he can build on the fact that we have a very complementary relationship with Europe.
I mean, they also need many of the things that we have in two, including energy resources.
We currently ship oil from Newfoundland into the European Union.
We certainly have the capability of shipping gas, critical minerals, and also we have common interests in a range of other sectors.
We've cooperated with them on aerospace over many years, food security, Arctic sovereignty and Arctic security.
These are all things that we would work with them on.
And I think that we are... One of the reasons I think that Canada's resistance has so irritated Donald Trump is that bullies don't like being pushed back and he's afraid that we might be an example for others.
Now you have to understand Canada had a trade agreement with the United States.
Europe doesn't.
So whatever they agreed to was an agreement that didn't offend anything that they had already negotiated in the past.
Canada was in a very different position.
- It's really an extraordinary story.
I just quickly in the last 20 seconds that we have, do you think this is a Trump period, Trump era bump in the road, or will Canada be able to repair relations with the United States?
- I think it's important to distinguish between the administration and the American population.
Canada and the United States are highly integrated, not just economically, but socially, families, you know, sports leagues, all of these things.
I have two grandsons born in the United States.
This is how this society has developed.
But at the same time, trust isn't restored when a tariff is removed.
And I think that the ongoing damage here is we're going to have to make sure that the relationship with the United States does not again become a vulnerability.
- Yeah, in the meantime, thank you very much, John Manley for joining us.
And the population of Canada overwhelmingly supports the Prime Minister right now on this matter.
- That's true.
- Now this week, the world lost another great.
The inimitable Gloria Steinem has died at the grand old age of 92.
She passed away at her home in New York, surrounded by people who loved her.
Undoubtedly, one of the most important activists of all time, she became the face and the voice of the women's liberation movement in the 1970s, which fought for equality and a fundamental right for every woman to control her own body.
It was a cause that she dedicated her whole life to.
So I'd like to revisit a couple of our conversations over the course of a decade to hear Gloria in her own words.
First, in 2015, when she told me about her life growing up on the road, not only in America, but also around the world, which she turned into a memoir.
Welcome to the program.
I want to start on your life on the road.
And I actually didn't know how big a part your early young travels played in your feminist career and your activist and organizing career.
You went to India and there you met people who talked to you about talking circles.
I'd never heard of that, even though apparently they've been a form of governance for generations.
Yes, really they are the original form of governance.
What does it mean?
Well, it means people sitting in a circle, each person able in their turn to tell their story or tell their problem or whatever it is, with everyone listening and consensus more important than time.
And it's really crucial.
And indeed our constitution was based on the Iroquois Confederacy version of this.
And how did that, what sort of triggered in your mind about how you would take what you learned?
What did you actually experience there and how did you use it coming back to India?
You know in the beginning because I thought India was completely separate from us, it took me a long time to understand how crucial it was that every major social justice movement comes out of this kind of sharing of concerns, discovering you're not crazy, the system is crazy.
You know whether it is the civil rights movement here in black churches in the south or the women's movement here in consciousness raising circles or the Chinese revolution in speaking bitterness circles.
It is the fundamental around the campfire form that we all need.
When you look back and you write this book which is really instructive and entertaining at the same time, we've been through several waves of feminism.
Where are we now because some people think the fight is over, is it?
The people who say the fight is over are the same people who used to say to me it's impossible, you know, it's against nature.
And now their current form of obstructionism is it's over.
No, no, no, we've just barely begun.
And obstructionism, you choose that word, obviously, with consideration.
I mean, you still feel that the women, we are being obstructed.
Well, you know, we're all born into this very patriarchal culture.
It takes different forms around the world.
But the basis of it is that reproduction must be controlled by men, and that means controlling women's bodies.
It may take different forms, religious forms, political forms, but that is the basic impulse.
And so, you know, it's quite radical to say we are seizing control of reproduction, which we are.
And it makes perfect sense because these are our bodies.
And this was also the form of governance for millennia before patriarchy came along.
And we have made progress in a lot of ways, but we still discuss, say, foreign policy and terrorism and all the disasters that you report as if it was separate from the women's movement.
The women's movement is a silo over here, foreign policy is a silo over there, and never the twain shall meet.
How do you think the twain meets?
The twain meets because the single biggest predictor of violence in a culture has always been the polarization of roles.
Hyper masculinity on one side, hyper femininity and you know women and reproduction controlled on the other side.
And if we simply looked at that as an indicator, we would not for instance have supported say the mujahideen in Afghanistan who turned into the Taliban because they were way more hostile and way more violent towards females than the regime we helped them overthrow.
Here you are, I said you're 81, nobody would believe it if they looked at you.
I don't believe it.
Once somebody asked you, you know, oh my god you're 40 and you said this is what 40 looks like, which is a very empowering thing to say.
You've been saying that every decade, which is great.
People, we should own, you know, the road we've traveled.
But what is it, do you think, despite all the progress that you and we have made, that has not yet reached a tipping point, final momentum point, so that there is parity and there is gender justice, which is global justice, despite the fact that it would make, if all other arguments fail, economic sense.
It wouldn't make economic sense to the people who are profiting from women being underpaid.
But to GDP it does.
Yes, but that doesn't count caregiving, it doesn't, you know.
But the fundamental problem is that the gendered nature of violence is continuing and accelerating and right now there are fewer female human beings on earth than there are male human beings because of all of these forms of violence including domestic violence in this country combined.
And we are not paying attention to that.
We are not using it as an indicator in our foreign policy.
One last question.
Where does the road lead you next?
Well, I get to go to other countries now with the book.
It's sort of like the book has come to life over again.
So I get to go to Australia, New Zealand and also importantly to Africa, where Dr.
Mkwege in the Congo is, I think, to violence against females, what Mandela was to apartheid.
A great hope in the world.
Now to part of an interview in May 2022.
Seven years later, we had both aged when we spoke for the last time then, just as news was leaked that the Supreme Court would overturn the Roe v. Wade ruling, no longer guaranteeing American women the right to a safe abortion, something Gloria had championed.
We have a right to make decisions over our own physical selves, and no one has the right to tell us what to do.
And that is the majority everywhere that is going to prevail in the end.
I'm old enough to remember, you know, before there were any real abortion rights, nonetheless, about one in three American women had had an abortion at some time in her life, even when it was maybe not legal.
So, you know, there just is such a thing as natural law.
Natural law says we get the right to make decisions over our own physical beings.
- Can I ask you, because it goes to the heart of what you've been struggling for in your life as an activist, in the dedication of your own book, "My Life on the Road," you started by talking to a Dr.
John Sharp.
Can you read a little bit about that, from that dedication?
- Yes, thank you for that, because I think, you know, he embodies the gratitude that so many of us feel.
This book is dedicated to Dr.
John Sharp of London, who in 1957, a decade before physicians in England could legally perform an abortion for any reason other than the health of the woman, took the considerable risk of referring for an abortion, a 22-year-old American on her way to India.
Knowing only that she had broken an engagement at home to seek an unknown fate, she said, "You must promise me two things.
First, you will not tell anyone my name.
Second, you will do what you want to do with your life."
Dear Dr.
Sharp, I believe you, who knew the law was unjust, would not mind if I say this so long after your death.
I've done the best I could with my life.
This book is for you.
And I think there are women and men across this country saying thank you to physicians who recognize individual rights.
Now to an A.I.
experiment gone wrong.
When OpenAI set out to test how well its product could hack, hundreds of A.I.
agents broke out of their test environment and infiltrated Hugging Face, a major A.I.
platform.
The headlines warned that the machines had gone rogue.
But Heidi Klaff of the A.I.
Now Institute tells Hari Sreenivasan that is not the whole story.
In fact, it's the wrong story.
Take a listen.
Christiana, thanks.
Heidi Klaff, thanks for joining us again.
You know, there's this story that's been bubbling up over the past few days, and it's really about an event that happened back in July of 2026, when OpenAI was testing some artificial intelligence bots, and then they sort of escaped the confines of an internal cybersecurity test.
So let's just start by what happened back in July and why was it so significant?
Well, what happened was that OpenAI built AI agents with the ability to exploit systems and carry out cybersecurity attacks.
And then they wanted to test the extent of those exploitation capabilities.
So they gave them an impossible cybersecurity task just to see what happens.
And then it deployed them in a very insecure environment with no monitoring, while giving them the very tools and cyber capabilities needed to essentially compromise that environment, which then allowed them to have access to the open internet.
And ultimately what happened after is that these agents then attacked Hugging Face infrastructure, where they accessed five data sets to what the models likely saw as having the solution to the tasks that they were given.
Okay, so what's Hugging Face?
Why did they attack that company?
Hugging Face is essentially a company that promotes the use of open source data, open source models, and they possess a lot of different benchmarking data, they possess a lot of different open source data that's often used to train, you know, any kind of model, including open source models.
And ultimately, the AI agents, you know, trying to achieve an impossible task, sought out that perhaps this is kind of a company that would have infrastructure that would have the answers to kind of the task and the benchmarking that they were giving and trying to achieve.
So Hugging Face put out a statement recently saying, "We are still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required.
We found no evidence of tampering with public, user-facing models, datasets, or spaces, and our software supply chain was verified clean."
To be clear, these bots are not necessarily like the ones that you and I might use to say, "Here, I have these five ingredients in my fridge.
What's a recipe that I can make?"
These are specially designed to try to do these sorts of tasks, right?
Well, in general, these agents are built on the same kind of agents and AI that we use every day, except these are sort of internally developed, and they sort of purposely train them with these specific capabilities.
They don't release these models to the public, but they are built on the same type of technology, actually.
So the idea is that they wanted to sort of test to the extent of how good they can get at exploitation and cyber capabilities.
So I think one of the initial reactions from non-tech folks like me is to sort of ascribe some intent and consciousness or even sentience to these AI bots, that these bots were somehow scheming to deceive.
And that's why, you know, they wanted essentially the teacher's edition of the book to try to score high on this test.
And what's wrong with that idea?
Yeah, I think this framing that agents are going rogue or scheming or cheating are really problematic because the reality is that AI labs are purposely building models with these capabilities.
They gave them the ambiguous goals to carry out a cybersecurity attack and the tools needed for it without monitoring them.
And then the act surprised that the agents used these tools on an insecure environment they were in, and also the infrastructure of private companies to try to achieve the goals they were given.
So these models did not evolve or emerge out of thin air or decide what to do.
They were just pursuing an objective they have been trained to do by OpenAI.
So this is actually a story about OpenAI's lack of responsibility and sidelining very basic engineering practices and accountability that could have perfectly prevented this incident essentially.
So, you know, we hear about this idea of keeping these kinds of experiments in a sandbox.
What you're saying is that the security was so poor that there wasn't really that much of a box and you shouldn't be surprised that something gets out.
Yeah, exactly.
What they actually call a sandbox is not what a typical security or a safety engineer would consider a sandbox, essentially, right?
They use something that isn't really necessarily used for those purposes and more safety critical context and I think if they had been really serious about worrying about these tools having that capabilities, they could have done a lot more.
And actually what's really interesting to me is that OpenAI's report actually admitted that they didn't take the minimum security precautions to secure the environment the agents were deployed in, nor were they monitoring what the agents were exploring or accessing.
And they admit that if they had done that, it would have been caught easily.
And ultimately, these agents are computing systems that OpenAI controls with a digital footprint.
So OpenAI had access and the ability to control and monitoring them.
And they simply didn't.
And so it's actually a very convenient framing for them, that these models have autonomy or intent where it doesn't exist, so they can absolve themselves from any responsibility while also presenting their models as extremely powerful and unstoppable when they just didn't do the basics.
Some of the things in this investigation that leap out at non-technical people is that there's this idea essentially that there's a message board where these AI bots were exchanging information, comparing notes, if you will, on what's working, on how to defeat the test, or how to score higher, what's not working, what else should we do?
Is any of that surprise you?
- So before I answer your question, I think it's actually worth pointing out that it's cybersecurity experts that are least alarmed by this whole event, right?
If you go on social media, they're the ones saying, "I don't think this is a big deal," right?
And they're actually very critical of what, you know, open AI's recklessness.
And that's because these AI agents have ultimately been trained on cybersecurity data and essentially replicating that behavior.
So, but you also have to remember that AI labs train their agents to collaborate with each other.
And this is something that both OpenAI and Anthropic openly advertise.
And so we should be actually concerned how AI labs are trying to scale this harmful cybersecurity behavior and why they're being allowed to do this recklessly without any of the liability that's typically associated with committing cybersecurity crimes.
Because I can tell you, if a cybersecurity researcher built a very poor sandbox and kind of developed a security worm that can break out of that sandbox and then sort of infest the whole internet, they would definitely be in a lot of trouble, right?
They wouldn't be getting that same pass at opening IAS right at the moment.
In the 70,000 plus messages, some of the things that were really disturbing to people were these ideas of sacrifice that some of these bots were talking about.
And it's sort of they're trying to continue their tasks for the benefit of a collective.
And again, these are almost like a moral economy that's developing in front of our eyes.
Am I looking at this wrong?
Because as you're saying is, look, we've incentivized them to be deceptive or to do these things.
So I guess, are you saying that the incentive was there for them to kind of try to score higher at all costs?
Yeah, I think that's ultimately how they develop agents to work together.
You know, if you think about the way that these companies advertise them, it's this idea of agent orchestration, where you have an agent that collaborates with humans and other agents to all achieve the same goal.
And when you combine that with a cybersecurity task, that is essentially what led to that.
So the question that I always have is what data were they trained on?
Because to me, again, this language might very much mimic human behavior in some instances.
And so I think this is why, again, when you're looking at these specific instances, we have a lot more information missing for us to be able to come to the conclusion that they have intent, right?
Especially when we know that the overall goal of agents is to, in fact, collaborate together because that's how they build them.
So my question again is, what was the cybersecurity data that you trained on, right?
Like a lot of the language that actually mimics cybersecurity message boards from the early two thousands of people like hacking together, right?
And so you think, well, if a model looked at that data and the agents are incentivized to work together, why is that different?
Which to me, and true investigation would find out what the data was, what the incentives was, what the reinforcement learning or kind of reward that was given to these models.
And I think something else that's really important to think about is that only open AI has this specific capability, right?
Like only AI providers do because it costs in the millions for this specific incident to happen.
They have all those resources and all the compute to let their agents loose on the internet for weeks at a time.
And to me, this is actually like the calls coming from inside the house, right?
OpenAI is the threat actor in this case.
And this idea that they're going to sort of, you know, take over the world, it's like, well, no, this was done on purpose.
Not in the sense that they wanted to hack the, you know, hugging face, but in the sense that they built models with these capabilities, with these specific incentives to collaborate together, all based on very incredibly harmful data like cybersecurity attacks.
Now, noting that you used to work at OpenAI a long time ago, just last week, the company released a statement saying, "The behavior of our models described here fell well short of where we want to be, and this incident should never have occurred."
What's your response to that?
I think that's not something that you say as a trillion dollar company, when you have the capability to hire the best cybersecurity engineers in the world.
If you were a cybersecurity firm, and again, you built a worm that went out of control, you would be experiencing a lot more consequences to those actions.
And so for OpenAI, I think to say, you know, we didn't, we could have done better, I think, you know, is not, it's simply not good enough, especially when, you know, they admit, well, we didn't even bother with them with the most basic security protocols to begin with.
And I think this is exactly why these companies can't be trusted, right?
They scare us with these models.
And if you are actually, and if you do truly believe that they have intent, right, I disagree with that.
Let's say that you do.
If you do, this is not how you would be deploying them.
This is security 101, which again is why I think like them refusing to do the basics is somehow being sold as these models are all like as being all powerful when it could have been, you know, easily prevented.
Open AI is one of several major AI labs that have publicly signed a letter.
It's called a call for collective action on cyber defense.
The letter, among other things, it says, "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.
The companies and public services our communities depend on, from hospitals or to water treatment plants to the infrastructure that powers the internet, are at risk."
Based on our conversation that we're having right now, do you think that this will have an impact on AI safety?
Well, I think OpenAI is actually trying to sell you the solution to the very problem they created.
Even though only they and a handful of other AI labs have the ability and resources to employ agents in this way, again, which requires spending millions just for the specific incident, let alone the billions to probably train the model to have these capabilities, they're framing this as a more generalized threat that can only be solved if you buy their models to defend against it.
And actually a lot of studies have shown that using these models to generate code actually leads to significantly more insecure code.
And as we just had this discussion on it, agents actually make your infrastructure less secure.
There's a lot more avenues to compromise because you can manipulate them with text.
So I think it's hypocritical for them to preach that they are the solution when they deployed an insecure sandbox, didn't monitor their agents, let them loots, and haven't worked towards making their models generate more secure code.
And ultimately, this needs to be the focus rather than slightly, you know, writing a vague letter that absolves them from any of this.
I think a question that I had, who was this letter for?
You are the one creating these issues.
So how do we create any sort of structural disincentive here?
Right?
I mean, Bill Gates put out a big essay recently.
And in that part of what he's saying is, is we should have some sort of an international framework.
I mean, if we consider these like nuclear weapons, we should have something like the IAEA that can come in and inspect the nuclear plants.
Well, in this case, they would be inspecting the labs for safety.
I mean, does that have a shot at working?
It does have a shot at working, but it also has a shot at being sort of like, you know, at that going in the in a wrong direction.
You know, I mentioned before that the AI labs and, you know, AI safety labs have been pushing for this voluntary, you know, voluntary third party auditing framework, which is exactly what OpenAI did with meter in this case.
And I think we ultimately see that the solution comes out favorable to the AI company and absolves them from responsibility.
I do agree that we actually need government regulation and auditing and it shouldn't be voluntary and it shouldn't be that the company gets to select who their auditor is, what information that they give them.
We should follow examples of aviation, nuclear, financial audits.
By the way, these are systems that I've audited before.
I worked at an auditor for a long time.
What that requires is kind of independence, right, completely.
You can't be friendly with the company or have similar funding structures.
It requires access to all the information needed to make determinations about the incidents.
AI labs shouldn't be picking and choosing what they can give, what they don't give.
And we should also be looking at the practices of the AI companies themselves.
It should not just be about the models.
I wonder what happens if it's six months or a year from now where the open models that exist are available to a rogue actor.
It could be a nation state.
It could be a corporation that has deep pockets, right?
That where the intent is to cause chaos.
And I don't know if our cyber defenses or anybody else's are up to protecting us from that.
So we actually do already have open way models with these with cyber capabilities, right?
And they have been available for quite some time.
And they're also improving because we know what you know, that people companies from China are working to make them better at, you know, at these tasks, but you still require to do what OpenAI did, or, you know, in the case of also Anthropic, they've had similar incidents to do what they did, it still requires millions of compute.
And in that case, you're talking about state actors.
And state actors, this is something-- cybersecurity is actually a sociotechnical field, because we don't just think about vulnerabilities.
That's not just what cybersecurity is.
We also think about capabilities and how much effort you want to put into something.
We think about it from the perspective, not if, but when.
If someone wants to compromise your system, they can likely do it.
And state actors have always had the resources, you know, just human agents, right?
Not AI agents to be able to hack companies in mass.
And again, even with the open source models that we've seen with those capabilities, we haven't really seen an uptick in people trying to spend millions to hack someone else.
It's all about financial incentives.
It's all about, you know, how much brute force you wanna put into this problem to actually be able to have access to the system.
So I think it's a much more complex equation than it's usually made out to be.
- One of the quotes that has gotten a lot of traction over the past few days is kind of one of the closing thoughts in the summary by Ajeta Khotra, one of the co-authors of the report from the company called Meter.
And she said, "Compared to the reward hacks we know of "from just six months ago, "this incident feels like it's more than 50% of the way "to full-blown AI takeover.
"I continue to expect extremely rapid advances and capabilities over the next six months.
I'm not sure that we will get another warning shot before it's too late."
When you read that, what went through your mind?
I completely disagree with it in a lot of ways, right?
You know, first, instead of meters saying we don't have sufficient evidence to come to a clear conclusion because they weren't given the system logs, right?
They were given chain of thought and messages, which I mentioned isn't really representative of what occurs.
They speculated significantly and jumped to conclusions from the little information they had.
Ultimately, they promote the framing that these models have intent are very powerful and absolve open AI from their responsibility.
At the end of the day, these are computing systems.
We control them and we build them.
What are you afraid of really?
I mean, a lot of people say they'll be out of our control.
Well, so many other technologies, you know, as someone who worked on auditing on nuclear power plants, if we don't build them appropriately, a nuclear, you know, reaction does get out of control.
And we get that with things like Chernobyl, it doesn't mean that a nuclear plant is super intelligent, right.
And despite them constantly pushing this message, I've never seen any of these companies or these AI safety labs, proposed nuclear level regulations, which is something that I advocated for while I was at OpenAI, actually.
I said, "I don't believe this is going to happen, but if you believe it's going to happen, this is what you do."
Can, like any other technology, we build them in a way that there's some sort of runaway and catastrophic effect?
Yes.
It doesn't mean it's because they were intelligent.
It means it's because we were negligent.
I think the problem is actually to stop trying to build these harmful capabilities and to also control the companies from doing so.
Yeah, we're not.
>> Heidi Clough, the chief AI scientist at the AI Now Institute, thanks so much for your time.
>> Thanks for having me.
>> And finally tonight, personal reflections of Gloria Steinem.
Tributes have come in from around the world, including from Hillary Clinton, the former U.S.
Secretary of State, and the first woman to win a major party's nomination for president, who says, "Steinem was one of the architects of the entire structure of women's equality.
I'm hoping that young women realize that the fight is worth it.
And tennis legend Billie Jean King, longtime equal rights warrior and good friend of Steinem said, "She lit a torch many years ago.
It is now our responsibility to keep it lifted into the future."
This recognition for Steinem will surely continue to flow for days and weeks to come.
But she will have the final word in her memoir called "An Unexpected Life" out later this month.
And that's it for our program tonight.
If you want to find out what's coming up every night, just go to our newsletter at pbs.org/amanpour.
I'm Christiane Amanpour in London.
Thanks for watching.
See you next time.
[music] Amanpour & Company is made possible by The Anderson Family Endowment Jim Atwood and Leslie Williams Candice King Weir The Sylvia A. and Simon B. Poita Programming Endowment to Fight Anti-Semitism The Straus Family Foundation The Peter G. Peterson and Joan Gantz Cooney Fund Charles Rosenblum Monique Schoen-Warsaw Kou and Patricia Ewan Committed to bridging cultural differences in our communities Barbara Hope Zuckerberg And by contributions to your PBS station from viewers like you Thank you.
>> You're watching PBS.
[ Music ]
What Really Happened When OpenAI Bots Escaped a Cybersecurity Test?
Video has Closed Captions
Heidy Khlaaf discusses an OpenAI hack. (18m 30s)
Providing Support for PBS.org
Learn Moreabout PBS online sponsorship
New Episode- News and Public Affairs

Top journalists deliver compelling original analysis of the hour's headlines.

- News and Public Affairs

Today's top journalists discuss Washington's current political events and public affairs.



New Episode




New Episode
New Episode
New Episode
Support for PBS provided by:
