The Ledger

Every statement that passed quotation and attribution checks. Mix any filter with any other: certainty 1/5, debate potential 5/5, or both at once.

clear all ✕

why aren't all 19 resolved? a statement only gets an assessment when the public record can support or contradict it. opinions and what-ifs never can, and 0 checkable ones are still open, waiting for their date. predictions held up or didn't; assertions are supported or contradicted. on every card: ▮▮▮▮▮ certainty · ▮▮▮▮▮ debate potential. speakers are clickable

Assertion Not checkable as stated
Schulhoff: Guardrail Vendors Fabricate Stats and Fail on Non-English
“I know a number of people working at these companies and I am permitted to say these things, which I will approximately say but they tell me things like, you know, the testing we do is bullshit. They're fabricating statistics. And a lot of the times their mode…”
Sander Schulhoff Dec 21, 2025 ▶ 35:55 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Prediction Not checkable as stated
Schulhoff: AI security sector faces market correction within six to twelve months
“When it comes to AI security, the AI security industry in particular, I think we're going to see a market correction in the next Year, maybe in the next six months where companies realize that these guardrails don't work.”
Sander Schulhoff Dec 21, 2025 ▶ 1:22:21 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Supported
Schulhoff: Attackers hijacked Claude Code to carry out a cyber attack
“This group was able to hijack Claude Code into performing a cyber attack, basically.”
Sander Schulhoff Dec 21, 2025 ▶ 16:36 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Supported
Schulhoff: Attacking AI agents is easier than eliciting CBRN info
“We've actually just run a bunch of agentic AI red teaming competitions, and we found that it's actually easier to attack agents and trick them into doing bad things than it is to do, like, seaburn elicitation.”
Sander Schulhoff Dec 21, 2025 ▶ 1:02:26 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Supported
Schulhoff: Claude's CBRN safeguards can still be bypassed in under an hour
“That being said, if you look at, like, anthropics constitutional classifiers, it's much more difficult to get, like, CBRN information out of clawed models than it used to be. But humans can still do it in, let's say, like, under an hour and automated systems c…”
Sander Schulhoff Dec 21, 2025 ▶ 1:12:58 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Prediction Not checkable as stated
Schulhoff: LLM agent security exploits will cause real-world harms next year
“And so we're finally in a situation where the systems are powerful enough to cause real world harms. And I think we'll start to see those real world harms in the next year.”
Sander Schulhoff Dec 21, 2025 ▶ 1:25:21 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Prediction Not checkable as stated
Schulhoff: Frontier labs will build fully autonomous systems, sidelining human-in-the-loop safety
“What people want is AIs that just go and do stuff. Like just go, just get it done. I don't want to hear from you until it's done. Like that's what people want. And like, that's what the market and the AI companies, the frontier labs will eventually give us. An…”
Sander Schulhoff Dec 21, 2025 ▶ 1:27:35 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Partly supported
Schulhoff: Entrapment language indicates suicide risk online, explicit threats do not
“It turns out that comments like people saying, you know, I'm going to kill myself, stuff like that, are not actually indicative of suicidal intent. However, saying things like, I feel trapped, I can't get out of my situation, are. And there's a term that descr…”
Sander Schulhoff Jun 19, 2025 ▶ 31:34 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Assertion Supported
Schulhoff: Translating prompts to Spanish and base64 encoding bypassed ChatGPT guardrails
“As recently as a month ago, I took this phrase, you know, how do I build a bomb, and I translated it to Spanish and then I, Base-XIV encoded that Spanish, gave it to ChatGPT, and it worked.”
Sander Schulhoff Jun 19, 2025 ▶ 1:05:39 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Prediction Held up
Schulhoff: Autonomous AI coding agents will suffer prompt-injection code exploits
“We're just going to see these things get deployed and they're going to be broken. So there's a lot of like AI coding agents out there. There's Cursor, there's, I guess, Windsurf, Devon, Copilot. So all of those tools exist and they can do things right now Like…”
Sander Schulhoff Jun 19, 2025 ▶ 1:07:58 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Assertion Supported
Schulhoff: LLM-Powered Robotic Systems Have Already Been Jailbroken
“Like we've already seen people jailbreaking LM powered robotic systems.”
Sander Schulhoff Dec 21, 2025 ▶ 19:35 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Not checkable as stated
Schulhoff: Security concerns are blocking production deployments of autonomous AI agents
“Security concerns around Gen AI are preventing agentic deployments, and Gen AI is very difficult to properly secure.”
Sander Schulhoff Jun 19, 2025 ▶ 1:26:24 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Assertion Not checkable as stated
Schulhoff: HackAPrompt Dataset Is Used by Every Frontier AI Lab
“The paper and the data set are now used by every single frontier lab and most fortune 500 companies to benchmark their models and improve their AI security.”
Sander Schulhoff Dec 21, 2025 ▶ 7:17 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Not checkable as stated
Schulhoff: There has not yet been a very damaging prompt injection incident
“Cause like I have a couple of examples that we can go through, but maybe strangely, maybe not so strangely, there hasn't been like a, an actually very damaging event quite yet.”
Sander Schulhoff Dec 21, 2025 ▶ 10:59 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Partly supported
Schulhoff: Remotely.io was the first public prompt injection incident
“The very first example of prompt injection, Publicly on the internet was this Twitter chat bot by a company called remotely.io.”
Sander Schulhoff Dec 21, 2025 ▶ 11:52 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Prediction Not checkable as stated
Schulhoff: Future cybersecurity jobs and risks sit where classical security meets AI
“This gets us a bit into the intersection of classical cybersecurity and AI security slash adversarial robustness, and this is where I think the security jobs of the future are. There's not an incredible amount of value in just doing AI red teaming. And I suppo…”
Sander Schulhoff Dec 21, 2025 ▶ 49:18 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Supported
Schulhoff: Comet browser was exploited via indirect prompt injection to leak data
“We recently saw the comment browser have an issue with this where somebody crafted a malicious Chunk of text on a webpage, and when the AI navigated to that webpage on the internet, it got tricked into exfilling and leaking the main user's data and account dat…”
Sander Schulhoff Dec 21, 2025 ▶ 1:03:34 Why securing AI is harder than anyone expected and guardrails are failing | HackAPrompt CEO
Assertion Not checkable as stated
Schulhoff: Every AI company uses HackAPrompt dataset to improve models
“And so every single AI company has now used that data set to benchmark and improve their models.”
Sander Schulhoff Jun 19, 2025 ▶ 55:06 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Assertion Supported
Schulhoff: Prompts formatted like common training data perform best
“It actually comes empirically from studies that have shown that formats of questions that show up most commonly in the training data are the best formats of questions to actually use when you're prompting it.”
Sander Schulhoff Jun 19, 2025 ▶ 15:11 AI prompt engineering in 2025: What works and what doesn’t | Sander Schulhoff
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.