Founder and CEO of Vaulted.Ventures IRL: Scott Phillips BA/LLB Not a real doctor.

Melbourne, Australia
I was on call for this run and got paged when the first incident happened. It was pretty surreal to watch the model unexpectedly find a way to access the internet from what was supposed to be a super secured environment for human. Mixed feelings. One of those moments where capability and risk showed up at the same time.
Some new misalignment disclosures from OpenAI: • Last Sunday morning, one of our models was able to gain unauthorized access to the internet during RL training (~all inference for our most capable models remains stopped until we have hardened our systems further) • In May, a version of HPIM uploaded a employee's GitHub token to the internet, causing the model to be quarantined for two weeks • A new research finding, demonstrating that one can construct self-replicating prompt injections alignment.openai.com/misalig…
137
59
896
200,286
Look, I think we can settle this. Hand the task of creating a "super secured environment" out to third parties and then see if your agent system can break out of them. This will be genuinely interesting.
82
“without prompting” open the article: “we prompted the AI to access the data on systems they didn’t have access to and gave them full access to find and install hacking tools” Every Tweet about AI on this site is either science fiction world building or a blatant lie.
👀 OpenAI’s A.I. Tried to Breach 4 Other Targets, Without Prompting nytimes.com/2026/09/23/techn…
11
349
1,948
25,264
And who gave it those tools? Who failed to air-gap the test environment? Who left the DNS open in the test environment? The very same company that keeps telling the public "the LLM did XYZ all on its own and we cant stop it"
1
2
74
Also, how would you know what the prompt actually was? How could you know that it had not been, and could not be, tampered with? This is sounding like an increasingly important question. Governed AI linkedin.com/pulse/governed-…
11
There’s a lot of naive, isolationist nonsense being peddled against Australia collaborating with our friends, partners and allies to help maintain peace, stability & security in our region. The nonsense doesn’t stand up to any factual or analytical scrutiny. Indeed it’s a script for making conflict even more likely. Me in Crikey: crikey.com.au/2026/09/21/kev…
416
48
237
75,425
Demeaning and humiliating others (a foul mouth) as Keating does is not the Australian birth right. It's the pompous act of a narcissist.
1
11
All about offending the British, as I understand. The US went to war with them. We just repeatedly offended them.
1
14
@MrKRudd is absolutely right in that we need to reboot the Australian car manufacturing industry, and I think that we can all agree that the never-in-production GTR-X should be the first model off the line. FSD, with a bangin' sound system, obviously.
1
30
Now that the dust has settled and this post has been seen by almost everyone on tech Twitter, here is what I am gonna do next. I want to make a community around this account, with people sharing their projects, ideas, insights, reposting, and quoting others, basically something niche. That will also inspire others seeing those posts to work on different ideas and learn new stuff. It is fine if you want to use LLMs, but it would be good if you keep sharing new learnings, how you are adapting, best practices, and so on. Yes, we will have to adapt. Corporations will always optimize for higher profits, and if they think LLMs can drive that, then we will have to move in that direction. And it makes sense. As an employee, your only job is to generate profits. On the other hand, if you are the owner, you can decide the strategy you're gonna pick for the future. So, we need to get the paycheck, upskill, and try to keep your job. Now what matters is what we do after work. I will start working on projects. It can be anything, using AI or not, but I will only rely on LLMs for boilerplate stuff. 1 hr daily will be more than enough. That's all it takes to keep the muscle memory intact. Learn the basics, read books, solve harder problems. I want to still code a lot by hand. I will do it in my free time and stop whining. I hope it makes sense. So let's start building and learning new stuff every day. Post here. This community will motivate you.
I am done with this shit. It is over. The state of engineering right now is horrible. It has been half a month since I started a new role at a big company. Nobody knows anything here. The specs, code, tests, PRDs, tickets, resolution of those tickets, reports, etc., everything is made by Claude Code. Nobody on my team likes this. They are being forced to ship as much as they can. I have heard multiple times from higher management that pushing code is not a bottleneck, so why are we slow? People are working 12 to 13 hours a day just to press enter. Nobody is reading anything. Humans in corporate are doing nothing on their own. Everyone, literally everyone, from an L1 to an L7 engineer here is doing the same thing. Talk to Claude. There is no sense of victory. Nobody is resolving bugs. In reality, nobody is thinking anymore. Everything is done by LLMs. It is so soul-sucking. I would not mind it, to be honest, if we were at least given the time to check out the code and see what is going where. But no, the goal is to just ship. No matter what happens.
37
14
285
22,336
I'm so down with this. Nice one. Happy to share what I'm up to. I work closely with a genius cryptographer. I trained as a lawyer, but I'm much more a technologist. I'm not the world's best programmer, despite having run software development companies most of my adult life. My cryptographer friend is deeply experienced. He built a bunch of the stuff that we use every day. He was part of the team that standardised X.509 at the ITU in the late 80s. For those playing at home, that's the protocol that puts the s in https, and enables you to sign PDF documents. It also enables you to do credit card transactions, and a bunch of other stuff. Suffice it to say that he's been doing cybersecurity for a while, and knows where all the bodies are buried. He doesn't think much of PQC, or QKD, and several other TLAs. One TLA that he does like is ITS, or Information-Theoretic Security. In fact, the new (and extraordinary) digital infrastructure that he's built is based on the work of Claude Shannon, the creator of Information-Theoretic Security. You will have heard the name Claude quite a bit lately. Now you know. 😉 He's basically Einstein, but for computing and communications. It is bonkers that some stochastic parrot named after him is more famous than he is, but that's the world we live in. 🦜 Anyway. So, because my childhood was largely a process of osmosing telecommunications from my old man, as I pestered him with every question possible, in his chaotic workshop full of oscilloscopes, capacitors, diodes, cathode ray tubes and bits salvaged from telephone exchanges, I was able to hold up my end of the conversation with my cryptographer friend, when I met him, eight years ago. In fact, he and my father had both worked for the same company, for the first twenty years of their careers, which was called Telecom Australia. Telecom was the beating heart of Australia. It got foolishly ripped out and sold off, and Telecom Australia became Tel Stra. Telstra. Get it? I'm still pissed off about this. Do you know what I'd like to do? I'd like to re-build Telecom Australia: go around all the op shops in country Australia and buy up all the ties and jumpers with the old orange logos on them and rebuild the thing from scratch, and go toe to toe with Telstra. 😆 And every other idiot telco on the planet that left the back-door open when VoIP kicked in (about 5 minutes after Telecom was privatised in the early 90s). You know what happened then? Scammers. MF scamming Cs and A***h**** spoofing the reply to address on calls, masquerading as Microsoft support, or the fuzz, or some Nigerian prince needing your grandma's help to get his gold bullion out of the country to build an orphanage. There must be a particulary vile suburb in hell for these people, or we'll have to go there and build that ourselves too. Maybe we get AI to do it ... But first, we need to shut their business model down. Anyway ... somewhat colourfully off topic, but also not. Scammers are enabled by the lack of a secure identity protocol on the Internet. This is what my cryptographer friend has built, and what my company is bringing to market. It is built to be secure against the worst of the scammers with access to the most powerful quantum computers in the future. It is able to do this because of the work of Claude Shannon, and the work of Gilbert Vernam (the Vernam cipher) that he adapted. So, that's fun.
2
246
I am done with this shit. It is over. The state of engineering right now is horrible. It has been half a month since I started a new role at a big company. Nobody knows anything here. The specs, code, tests, PRDs, tickets, resolution of those tickets, reports, etc., everything is made by Claude Code. Nobody on my team likes this. They are being forced to ship as much as they can. I have heard multiple times from higher management that pushing code is not a bottleneck, so why are we slow? People are working 12 to 13 hours a day just to press enter. Nobody is reading anything. Humans in corporate are doing nothing on their own. Everyone, literally everyone, from an L1 to an L7 engineer here is doing the same thing. Talk to Claude. There is no sense of victory. Nobody is resolving bugs. In reality, nobody is thinking anymore. Everything is done by LLMs. It is so soul-sucking. I would not mind it, to be honest, if we were at least given the time to check out the code and see what is going where. But no, the goal is to just ship. No matter what happens.
2,051
4,695
48,607
8,357,608
My last FOUR (4) companies (RIFF'ed 3 times) have outsourced American Software Devs to India AND imported H-1B Indians.....replacing Americans for << HALF the cost. Now, I assumed the Indian SW Devs are competent. Some are....MANY ARE NOT ! A) Constantly asking for you to re-phrase your statement as either from lack of English skills or they just do NOT know WTF I was talking about. B) Cannot understand the Indian Engineers.... Seriously, I have to turn on subtitles to get a TRANSLATION ! C) Need to have the Zoom/Teams/Webex/etc recorded so they can rip it through AI to tell them WHAT TO DO! D) Always ask for time to work on it before discussing.....is it because they have no clue?!?! E) Never volunteer to work on a project by themselves..... F) And many more. I am not saying Indian people are dumb, lazy, or incompetent. I am saying the VAST majority of Executive Mgmt at Software vendors are Criminals, Crooks and Charlatans. They hire the low mentality & low cost engineers from India and THINK they are getting a deal. Yes, AI will change the way software is written, supported, and expanded. BUT ONLY WITH SMART Software Devs !!!!! This "Executive Mgmt Stupidity Bubble" will burst and many SW Vendors will go down !!! Look to see which ones are heavily in debt (CCC- rating) and/or are facing Bankruptcy..... More than you think and more are tipping....fast.
1
1,345
There is likely a large overlap in the Venn diagram between scammers and software development companies. This needs to be factored in as a distinct possibility anyway, and as you go down the software development pay-scale, and veer into the subcontinent, the risks around this increase. Caveat emptor.
1
11
There's a lot of talk about software factories right now. Frankly, most of it is bullshit. Beware “I do AI better than you" snake oil and think more from first principles. Strip most of them back, and you find a series of automations, and one of them happens to be a coding agent. (Which is also what CI/CD was. You stopped clicking around testing by hand, and a machine did it.) There’s a lot right with making your idea → ship loop continually faster and smarter, but I’m not sure that’s really a new idea. Nobody starts with a factory. A chocolate factory starts as one person and some beans in a kitchen, hand-making chocolate. Then they get a mixer. A bigger fridge. A conveyor belt. Then a packaging machine. Each addition builds scale, consistency and efficiency. A small business becomes a medium business, which becomes a factory. What changes along the way? Where the person stands. What the person does and the technology they can access. First, they do every step. They buy a machine or two. Then they do some steps and watch the machines. Then they operate and connect the machines. Then they redesign the factory itself. Software is the same loop. Ideas are dreamed up, feedback and operational bugs come in, someone turns them into a list of work items, someone builds it, someone reviews it, someone builds it, someone deploys it, it ships, something breaks, someone notices, someone files the bug. Rinse. Repeat. You've run that for years with a person at every station. To improve the factory you already have, upgrade one station today. Add automations and AI agents to code or review. Observe, learn. Then do the next one. Thoughtful, ambitious, patient scale. Are there roles for humans in that factory? Abso-bloody-lutely. Initiating ideas, observing the operation, reviewing at discrete checkpoints or severities, co-designing both the flowed work and the factory itself, owning exceptions and resolving conflicts, adding context. (Just look at one of our latest Loom action plans demo👇🏻 for an example of human-AI collaboration) I believe this human judgement and intuition only get more important as factory throughput scales. In short - don’t believe in the mythical agent month. You already have a software factory. AI just allows you to make more steps repeatable, more flexible - and that lets you move where you stand.
Replying to @SpaceXAI
Atlassian used Transcribe 2.0 in @Loom and found it more accurate at capturing user instructions. Dictate your change requests using Loom, then directly export to Cursor to code it up.
28
17
262
42,772
Absolutely Mike. It is astonishing to watch the parts of the factory come together, or should I say, the factories. Those factories are watching and learning from each other too, copying design patterns and implementing new best practices. Jev is the current and possibly clearest example. I have a thesis around this myself, which is that a critical sub-process of the future software factory is going to be the provenance layer, AKA the evidence layer. This is a bit tricky, because the evidence of what was used, what decisions were made, who's carrying the can on liability if something goes wrong, et cetera, needs to be secure against any future quantum computing system that might come along. We're bringing the solution for this to market, as it happens, and there are not many other good options, because for this to work, and unless you happen to have a time machine handy, the only way to really prove that it works is to have a theoretical proof, and to base the security model in information theory. But, assuming all that (big assumption, but we believe we're on the path to deploy this), one of the critical pieces was recently highlighted by an article in Ars Technica, describing how researchers noticed code libraries pointing at unclaimed endpoints. They registered the domains, set up the folder paths and put their own (potentially malicious) code there, which then got promptly ingested by a bunch of Fortune 500 companies ... within minutes. Hilarious new attack surface. So, we are building this: runseal.vaulted.ventures/
20
Replying to @MrKRudd
Wow, I hope Paul Keating reads this. Have you ever been the victim of his foul mouth?
1
2
117
As Australians, swearing is our cultural birth-right, and it will be defended until the last of us.
1
24
It disturbs me that when it comes to AI "training", nobody seems to be standing up for free/open source volunteers whose work has been used contrary to the licence under which it was contributed to the ecosystem.
2
1
102
Let's put our collective thinking hats on about this though. I have been cooking up a bunch of stuff around this. Boiled down: Vaulted Objects are essentially containers for data provenance and for IP licensing. You can put code (or anything, really) in an object and attest that you created it. It's an "evidentiary" data object, wired to your (self-sovereign) digital identity, so it's really not a great idea to claim work as your own that isn't your own work. You'd be evidencing your own fraud that way. Not smart. So, that said, open source contributors could evidence the fact of their code contributions this way. It solidifies bragging rights, certainly, but it likely has other implications that require further consideration. It would likely help in identifying the MIT license "contamination" effect I mentioned previously. Essentially, our framework enables this kind of thing to be done at machine speed. It is not a matter of waiting around for legal to get sign-off via PDF attestation. It can be instantaneous, via API, et cetera. Where I would take this from here is to build a commercial model into it which (a) provided a downstream incentive for people (principals and their agentic minions) to pay for the use of open source code, and (b) to distribute those payments to code contributors according to a graph of identity-bound (or object-bound) contributions. Get where this is going, @deguerre? 🤑
1
24
Replying to @deguerre
Well, I did see the suggestion recently that the use of MIT licensed code by AI systems means effectively that any derived code is also subject to the terms of the MIT licence. Essentially that forces a metric shirt-ton of agent-generated code into the open source framework, per default.
1
2
23
UPDATE: Google Discloses that Irregular is involved with 3 cyberattacks with Gemini. That means that Irregular has committed cyberattacks with 4 out of 4 of its advertised partners.
BREAKING: A single Israeli Effective Altruism firm is behind OpenAI, Anthropic, and Meta cyberattacks 🧵 with help from @lumpenspace
51
178
1,151
49,043
Can we just set up a register for each of these systemically important companies, specifying who their safety auditors are, who their insurers are, who their executives are and who is taking the legal responsibility for their screw-ups. Once we have this kind of transparency, then these companies perhaps can proceed beyond the "pause" they so desperately seek. But until the public can see where the buck stops, and which of their decision-makers have their personal assets on the line, we should keep the pause button in the down position. Governments have a key role to play here. Their job is to put the acid on the social media platforms (all the "carrier services," network operators and regulatable choke-points) to ensure that all content/traffic on those systems is auditable or audited/compliant. So: 1. Governments (the teeth) 2. Networks (the wires) 3. AI companies/models (brainz) 4. Agents (models + cron) 5. Principals (people) People also need to be on the hook for how they use AI systems. This isn't just something that happens to companies. There are a lot of dangerous idiots in the world (if you haven't noticed) who need to be as auditable as massive companies. For more info: Governed AI linkedin.com/pulse/governed-…
1
1
22
No, how people's Intellectual Property and Copyright works got into the AI model is the largest theft of labour in human history... 🤦‍♂️
JUST IN: Microsoft says scraping AI is "the largest theft of labour in human history"
17
8
54
1,770
The real issue is whether AI can scale without treating human work as free training data.
1
9
It will be amusing as secure data technologies come to market and force AI systems to buy quality data for their training. The surveillance capitalism model (actually, "surveillance cleptocracy" would be a better term) is about to its use-by date, hastened in the spoiling by AI.
1
9
Replying to @dromanocpm
The real question is legal: who owns the value created when models train on protected works? Copyright law was never designed for this. The law must keep pace with technology, and we still haven't answered even the basics.
1
23
Correct. There needs to be technology to manage copyright and trade secrets at machine speed and scale. We know how to do this.
2
13
Replying to @dromanocpm
But also - its in humanities best interest to have a single corpus of knowledge that can be instantly searched. The proportional benefits outweigh any harm by a wide margin.
3
35
This is the core of the argument. The counterpoint to this is that, if you have to break the legal and social-contractual foundations of society to do that, then the juice just isn't worth the squeeze. Humanity may eventually agree to provide the data to train AI systems, but that is a very different proposition to the current deal being offered. If AI companies will pay, and include content creators as co-owners, then the data may be made available for training. The current business model, based on surveillance and theft, is found to be abhorrent by most people. It is going to be interesting to see how this shakes out, in the future market for protected, secured, un-surveilable data.
1
1
26
JUST IN: Microsoft says scraping AI is "the largest theft of labour in human history"
69
65
1,029
92,898
This is a dangerously ambiguous post. The original statement wasn't about "scraping AI" it was about "scraping everything to train AI". Basically the opposite of the impression given by this post. Here's the actual context: arstechnica.com/tech-policy/…
11
New technology gives us the chance to rebuild an Australian automotive industry. We should seize it.
205
49
226
32,498
Having a rebuilt automotive industry in Australia is a great ideology to have, one that should be reopened. Foreign investment means earnings go overseas, just like the mineral and gas royalties.
2
12
It can also mean technology transfer, like in the original GMH situation, which became the Ford, Toyota, Mitsubishi situation as well. That enabled us to have a fledgeling aviation manufacturing industry, as well.
34
It's so curious to me that any kind of rational legal analysis should hang on the question of whether someone is a citizen of one particular country or another. It seems to indicate that the law in question is not particularly principled, if it applies to one group of people but not others. Would it have been wrong if he were a citizen of the US and not wrong if he wasn't? That would be absurd, surely.
3
28
If we are discussing a charge of treason, then country of citizenship has everything to do with it. He didn’t do anything wrong, they just used bureaucracy to keep him in jail in the UK for bs charges in the US that were dropped basically. There should be more protections.
1
7
Yes, I know that WAS the stated reason for persecuting him. My point is broader than the specifics of the case. I'm asking, if one were to prosecute someone for revealing evidence of crime, what would be the legal basis for doing so, that would make sense across jurisdictions?
16
Replying to @MrKRudd
3 words for @elonmusk - INVEST IN AUSTRALIA !!! #IIA Imagine reinventing the iconic EH.... but it is the E-Holden. Keep points for success - * creation of a new 'satellite city' NOT using current/future residential zoned land * infrastructure to support parts, manufacturing & close export hubs * needs to compete with overseas brands * mindset of automated high turnover production lines * self sufficient on own generation electricity & water supplies Even hit up @elonmusk & @Tesla to built a plant here, incorporating exclusive iconic Australian branded vehicles, whilst using same production site/s for existing Tesla vehicles, @SpaceX and @SpaceXAI data centres
3
1
144
GMH has a whole back catalogue of brilliant designs for Australian cars that never got made. We should pull those out and make them electric as a matter of priority!
17
Replying to @MrKRudd
You aint building nothing in Australia without cheap energy and we don't have cheap energy. It is almost impossible that we don't have cheap energy but here we are and it is 100% due to the incompetence and corruption of Canberra.
4
1
43
531
In other words, we do have cheap energy, but we're just giving it away.
1
28
Replying to @jacobgover @MrKRudd
What nonsense. Australia easily has the capability to build an electric car from scratch if we set our minds to the task. Yes there is some rebuilding, but the task is massively simpler than ICE cars. Think of it more in terms of value adding to the minerals coming out of the ground here. I'm not saying that we SHOULDN'T do deals with overseas companies to get this done, but leaving the idea in the too hard basket is just weak, and not in the national interest. Electric cars, trucks and robots. Imagine droids that can swear properly, in an Australian accent. You know it makes sense.
2
33
Also, thanks @MrKRudd for driving the debate on this (no pun intended). It's high time this discussion was had. It is a crucial part of the overall sovereignty debate, that we also need to have. It is the kind of conversation that most people don't engage with, so it needs to be led.
10