May 7, 2026 · 1h 16m · mad
OpenAI Board Member Zico Kolter: Modern AI Is Just 200 Lines of Code
gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions
In this episode of The MAD Podcast, Carnegie Mellon University professor and OpenAI Board Member Zico Kolter joins Matt Turck to discuss AI safety governance, adversarial robustness and red-teaming, reinforcement learning frontiers, and the underlying architectural simplicity of modern AI models.
How this conversation actually went
Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Matt holds 12.2% of the talking time here. How this is scored →
speaking balance: gold is Matt, purple is the guest (3 minute bins)
Zico strongly pushes back against the terms doomer and accelerationist, calling them inherently dismissive and pejorative labels used by both sides to avoid nuanced safety discussions.
Hardest push from Matt ▶ 58:48 Challenging Production Readiness of AI AgentsMatt refuses to accept Zico's initial confirmation that agents are in production, interrupting to ask specifically whether they should be deployed from a strict security standpoint.
Biggest teaching moment ▶ 47:40 Discovery of Universal Transferable JailbreaksZico educates Matt on the unexpected mechanics of GCG jailbreaks, explaining how adversarial suffix tokens optimized on open-source models surprisingly transfer to closed commercial models.
Matt holds his own ▶ 34:33 Contextualizing CMU's AI Legacy Against Industry PullMatt displays impressive industry knowledge by citing foundational CMU figures like Tom Mitchell and Andrew Moore alongside the Robotics Institute to challenge Zico on academic relevance in the compute era.
the scores for every segment, with the reasoning behind each
| Chapter | Topic | Matt as informed peer | Guest teaching | Guest disagreement | Matt pushing back | Why |
|---|---|---|---|---|---|---|
| Podcast Title Bumper | 2 | 3 | 1 | 1 | Matt asks introductory questions about how OpenAI's Safety and Security Committee operates in practice and mentions sitting on corporate boards. Zico explains the governance oversight role and how model release reviews work. | |
| The Preparedness Framework and Emerging AI Risks | 1 | 4 | 0 | 0 | Matt asks for internal organizational details. Zico educates the host on OpenAI's Preparedness Framework, detailing dual-use risk categories like biological and cyber hazards. | |
| Industry Progress in AI Safety vs. Expanding Control Surfaces | 2 | 4 | 1 | 1 | Matt asks whether safety progress is keeping pace with core capability progress. Zico details how models are measurably safer yet face exponentially expanding control surfaces as agents gain real-world autonomy. | |
| Model Scale, Robustness, and Red-Teaming Benchmarks | 3 | 5 | 1 | 1 | Matt references Gray Swan's massive red-teaming competition to ask about capability versus vulnerability. Zico explains that model scale alone does not deliver robustness, requiring explicit safety training and system-level monitoring. | |
| The Four Pillars of AI Safety Risks | 1 | 5 | 1 | 0 | Matt asks where safety issues originate. Zico lays out a clear four-pillar taxonomy ranging from simple model mistakes to existential loss of control. | |
| Debunking Accelerationism vs. Doomerism and Historical AI Pauses | 4 | 3 | 2 | 3 | Matt probes the accelerationism versus doomerism debate and references the historic 6-month pause letter. Zico rejects both polar labels as pejorative and corrects Matt's timeline on which model era spawned the letter. | |
| Global AI Safety Institutes and International Cooperation | 3 | 3 | 0 | 0 | Matt asks about global AI safety institutes and pivots to Zico's background. Zico recounts attending OpenAI's 2015 launch party and their early, contrarian bet on scale. | |
| CMU's AI Legacy and Academia's Role in the AI Era | 4 | 4 | 1 | 1 | Matt demonstrates historical context by citing notable CMU leaders like Andrew Moore and Tom Mitchell while questioning how academia competes with tech giants. Zico explains academia's need to pivot toward agentic research and fundamental science. | |
| Founding Gray Swan AI and Enterprise Security Offerings | 2 | 3 | 0 | 0 | Matt asks Zico to introduce his startup Gray Swan AI. Zico explains automated red teaming tools and enterprise firewalls for agentic workflows. | |
| Defining AI Security vs. AI for Security | 2 | 5 | 1 | 0 | Matt asks for clarification between safety and security. Zico delineates AI security from AI for security, emphasizing worst-case adversarial resilience over average-case benchmarks. | |
| The Breakthrough GCG Paper and Universal Transferable Jailbreaks | 3 | 6 | 0 | 0 | Matt asks about Zico's landmark 2023 GCG paper. Zico educates the host on how automated suffix optimization revealed universal, transferable jailbreaks across closed commercial models. | |
| Lab Responses, Safety Classifiers, and Reasoning Model Resilience | 3 | 5 | 0 | 1 | Matt asks how frontier labs responded to GCG attacks. Zico explains multi-layered defense stacks and why reasoning models with chain-of-thought traces are inherently harder to manipulate. | |
| Advanced Multi-Query Attack Strategies | 3 | 6 | 0 | 0 | Matt asks how builders should approach agent security. Zico explains complex attack vectors like indirect prompt injection when agents process external untrusted web or email inputs. | |
| Deploying Agents Safely in Production | 3 | 4 | 2 | 4 | Matt challenges Zico directly on whether agents should be deployed in production given security vulnerabilities. Zico defends deployment readiness subject to proper sandboxing before pivoting to mechanistic interpretability. | |
| Two-Year Outlook on AI Safety and Autonomous Capabilities | 3 | 5 | 1 | 0 | Matt asks for a multi-year outlook on safety and frontier developments. Zico explains why reinforcement learning on model-generated outputs refutes the idea that synthetic data causes model collapse. | |
| Continual Learning and AI Breakthroughs | 3 | 5 | 2 | 1 | Matt asks about continual learning and post-transformer architectures. Zico offers a contrarian view that specific network architectures matter much less than the core discovery of scaling sequence prediction. | |
| Career Advice for PhD Students in AI | 3 | 3 | 0 | 0 | Matt asks what advice Zico gives his PhD students. Zico emphasizes taking risks and encourages young researchers to ignore established academic orthodoxy. | |
| Building Modern AI in 200 Lines of Code | 3 | 5 | 0 | 1 | Matt asks whether Zico's 200-line LLM codebase includes pre-training and RL. Zico details how the core mathematical framework of modern AI is shockingly minimal, whereas real-world complexity lies in data and GPU infrastructure. |