
Loading summary
Alan Rosenstein
The following podcast contains advertising to access an ad free version of the Lawfare Podcast. Become a material supporter of lawfare@patreon.com lawfare that's patreon.com Lawfair also check out Lawfare's other podcast offerings, Rational Security Chatter, Lawfare, no Bull and the Aftermath.
Grainger Ad
If you work as a manufacturing facilities engineer, installing a new piece of equipment can be as complex as the machinery itself. From prep work to alignment and testing, it's your team's job to put it all together. That's why it's good to have Grainger on your side. With industrial grade products and next day delivery, Grainger helps ensure you have everything you need close at hand through every step of the installation. Call 1-800-GRAINGER click granger.com or just stop by Granger for the ones who get it done.
Mike
This is Mike. Mike's stuck in traffic. The only thing that could make this worse is if he promised to cook his date dinner at 8. Which he did, but it's now 7:30 and he's still on the 5. Good thing Mike has Grubhub plus with Prime $0 delivery fees, 0 stress, 0 Rush D dinner's covered and so is his reputation. Free Grubhub Plus. It's on Prime. Additional terms and fees apply.
Alan Rosenstein
It's the Lawfare Podcast. I'm Alan Rosenstein, Associate professor of Law at the University of Minnesota and a Senior editor and Research Director at lawfare. Today we're bringing you something a little different, an episode from our new podcast series, Scaling Laws. It's a creation of lawfare and the University of Texas School of Law, where we're tackling the most important AI and policy questions. From new legislation on Capitol Hill to the latest breakthroughs that are happening in the labs, we cut through the hype to get you up to speed on the rules, standards and ideas shaping the future of this pivotal technology. If you enjoy this episode, you can find and subscribe to Scaling Laws wherever you get your podcasts and follow us on Axe and Bluesky. Thanks for listening. When the AI overlords take over, what are you most excited about?
Kevin
It's not crazy, it's just smart.
Alan Rosenstein
And just this year, in the first six months, there have been something like a thousand laws.
Kevin
Who's actually building the scaffolding around how it's going to work, how everyday folks are going to use it?
Alan Rosenstein
AI only works if society lets it work.
Kevin
There are so many questions have to be figured out, and nobody came to my bonus class. Let's enforce the rules of the road.
Brian Fuller
Welcome back to Scaling Laws, the podcast brought to you by lawfare and the University of Texas School of Law that explores the intersection of AI law and policy.
Kevin
Today's episode takes you inside one of the most fascinating frontiers in tech. Not just building AI, but designing the internal rules, systems and guardrails that shape how AI enters the world. We're joined by a product policy leader at OpenAI, Brian Fuller. He's embedded in the high stakes, high speed work of translating innovation into impact. When the pace of model development accelerates, so too must the frameworks that ensure AI is safe, aligned and socially beneficial. So how do you design policy in real time alongside engineers pushing the limits of what's possible? And how do you make sure those breakthroughs don't outpace the public interest? This conversation explores the art of asking the right questions, but before a product ships and sometimes asking them loud enough to slow things down. Brian, thanks so much for joining the pod.
Brian Fuller
Thanks so much for having me, Kevin. It's a pleasure to be here.
Kevin
So if we were talking to someone 50 years ago, 100 years ago, who knows and said, hi, I'm Brian, I work in Product Policy, we'd probably need to have at least a five minute conversation in modern times. I think more folks have probably seen that friend on LinkedIn who's celebrating becoming Product Policy at company X, Y or Z. But for those who don't know or don't have that friend, what the heck is your job?
Brian Fuller
That's a great question. Okay, so Product policy is the group at OpenAI that sits within the strategy organization. And so we're strategic. We broadly set the strategy for the company's approach to safety and integrity issues. And then we try to help that strategic vision get realized. And there are kind of like two things that we do to help realize that vision. The first is that we advise product teams that are building stuff at OpenAI. We help them navigate safety and integrity policy and sometimes legal concerns. And the second thing that we do is we own all of the rules that govern user behavior on the platform. So what you're allowed to ask ChatGPT and what you're not allowed to ask ChatGPT, for example. And you know, I'm, I'm just going to do a quick plug. I'm firmly of the opinion that product policy with an OpenAI is the coolest organization. I know it's saying a lot because there are a lot of cool orgs, but this is a group of people that is just uniquely intelligent but also profoundly kind, which is Such a rare combination to have together. Like, you know, Josh, for example, right?
Kevin
You know, full disclosure, full disclosure to the listeners and or watchers. I have had a beer, maybe two with Brian and he is wonderfully enjoyable and frustratingly smart. And it's that combination that drives you wild because you think you can only be one. And yet here, Brian is definitely both. And I think that you testifying to that about your colleagues is even more impressive. But I want to come back to the actual product, I want to come back to the actual product policy role for just one second because I think a lot of folks hear the word policy and they assume, oh, Brian must be a lawyer or exclusively works with lawyers or is interfacing with lawmakers themselves or regulators. But you mentioned this strategy component which necessarily, as you mentioned, brings in some questions of what's profitable, what's best in the short run and the long term for the business interests of OpenAI. So how do you weigh or what are some of the factors that are driving your policy decisions and how does that kind of influence how you all come out on these very weighty, very significant questions?
Brian Fuller
Yeah, no, that's a great question. Okay, so this varies product by product, right? Because the company's business objectives change product by product. Like for ChatGPT, realistically, the company's long term objective is to grow the number of people who are using that product, demonstrate greater utility in that product. And so it's a really long term vision that you need to bear in mind. Whereas there are other products that we might release that are a shorter term vision with more concrete milestones that we're trying to hit on an accelerated timeline. And so you do have to balance out business interests against a host of other factors. The other factors that you're really strongly looking into include privacy considerations like how much data is used, in what way is it used, is it effectively communicated to users how that data is going to be used? Integrity considerations, like how strict are we setting up the systems that are going to be looking into what people are asking of a model? When are people penalized? When are they not? How are they informed that they're about to be penalized? Like, because of course the objective isn't to penalize people, it's to help people to do the right thing. So how do you set up those systems? So like it's, it's really complicated, but it's all informed by two big overarching things. The first is the company's longer term, like top level business goals. And the second is the regulatory and policy making environments in which we find ourselves. So knowing what policymakers are thinking about, talking about and caring about is ultimately really important to do this job well. Because you can't play chess effectively if you don't know all of the moves that are being made. So strategy. Yeah, yeah.
Kevin
Well, I think that some listeners would probably think, huh, are lawmakers really playing chess right now with respect to AI regulation? Or is it maybe something akin to dodgeball or something a little bit more sinister and maybe less intellectually driven? But I'll leave that for a different discourse. But I want to zero in in particular on how you kind of work with other parts of OpenAI to get a sense of what those key values are and key determinants are of what is the right policy to make sure users, quote, unquote, do the right thing. Right. And also how do you engage specifically with external stakeholders in that process? Because as well intentioned as lawmakers may be, let's just presume they're playing chess. There is a bit of a regulatory void depending on the jurisdiction, of course. But I think here in the US in particular, no one is really saying, oh, we figured out AI policy, OpenAI, anthropic, so on and so forth. They know exactly what they need to do to adhere to the specific rules and goals we have for AI. So how do you make sense of all the different stakeholders who are involved in some of these decisions?
Brian Fuller
Yeah. Okay, so I'll break that question down into two parts. Right? There's internal stakeholders and then there's external stakeholders. I'll tackle the external stakeholders piece first. So we have a small group of external policy advisors that we can call on. We also have some people outside the company who do red teaming for us. We like to utilize both groups to get advice from policy experts and also security experts. Now, we don't rely on a huge enormous group of people for this work. And there's a good reason for that, which is if you're doing work for one of the world's most valuable companies, I think you rightly expect to be compensated for your time. And if you're being called upon a lot to do that kind of advice work, it's a lot easier to just hire that person and bring them in house because it makes the whole getting paid thing a lot more streamlined. So that's number one. Number two, as far as the like external regulatory environment piece, I guess I have a bit of a confession. I Doom scroll Political news.
Kevin
Wow, that is. That is a rough existence, sir.
Brian Fuller
I'm sorry for you know, it's a little bit dark right now for some people. Let's not get into that. But this isn't really helped by the fact that we get a lot of newsletters internally about the latest in AI regulations. So my broader team is just about as committed as I am to being the first to know what's happening both in Brussels and in the Beltway. And so I'm constantly getting pings from people going, you know, did you hear what Vice President Vance said? Did you? Have you heard about the latest EU regulations that have been proposed? It's. It's wild, man.
Kevin
It's a lot to keep track of. I mean, I think that folks in a sort of US bubble will say, oh, my gosh, just the regulatory chaos at the state level, at the federal level would alone elicit a sort of frantic mentality of, how the heck do I stay on top of all of this? But to your point, you all have to be asking, what's Japan doing? What's happening in the eu? What's China thinking about? Just keeping tabs on all of that seems nearly impossible. And I just want to add to the difficulty of your job, which is to say there's some speculation and I don't want you to address this. And no harm, no foul here, that, you know, it appears as though OpenAI is seemingly always ready to follow on a product announcement by one of its rivals with its own product announcement, just by some miraculous timing. This seems to always happen. And the hunch from maybe some external folks would be, wow, maybe OpenAI occasionally has to push faster on releasing a product than intended. In that hypothetical world of having to perhaps move very quickly, how do you all balance that sort of competitive pressure to remain on the frontier of whatever's happening with instilling the values underpinning your product policy work?
Brian Fuller
Yeah, so I. You said that I didn't have to address this, but I'm going to do it anyway. Okay. So I think. I think you're touching on something that a lot of commentators touch on, which is that there's this impression that AI companies are competing against each other and are deeply reactive to what's happening in another lab. That I think is true for some of the companies in the field, but I have not seen that at OpenAI. I genuinely have not. Like, we're interested in what are. In what other labs are doing, not because we feel this, like, frantic need to murder them on the field of economic combat, but rather because we're genuinely excited by the technology and the ways it's advancing. So if someone else is doing something really cool, we're going to look at that not because we feel like we have to copy them, but because it's just really cool. Like, you know, look, I think it's the difference between being motivated by money and being motivated by advancing the state of the art, advancing scientific progress. Like, I'm not talking smack about anybody, like, I need money to buy my groceries just like anybody else. But I think that commentators like framing this as a cutthroat game of technocrats skullduggery or something, since it, like, it plays better in the news. It's more exciting.
Kevin
Anytime I see a headline with skullduggery that's. I'm definitely clicking that.
Brian Fuller
Yeah, that's a. Yeah, that's a. That's a technical term in the policy world, of course. You know, in reality, we're just over here trying to like, make some cool stuff.
Kevin
Right, Right. Well, I will say you do make a lot of very cool stuff. And sometimes it doesn't always work as intended. I think listeners will be well aware of a particular model perhaps having some sycophantic tendencies that no one wanted to see. And yet it was released into the wild, being very appeasing and celebrating all of my chillingly good questions that I was asking. And it did make me feel pretty good for a while. But how does something like that happen? We've seen a postmortem on the technical side exploring what may have gone wrong with ChatGPT4 and those sycophantic tendencies from a product policy perspective. Who dropped the ball, Brian? What. What happened? What went wrong?
Brian Fuller
Look, I, I think this is a really tough one, right? Because, okay, you and I are in conversation right now. As a good conversationalist, you want to make a sign that you understand and empathize with the person to whom you're communicating. Like, people do this in a lot of really important but subtle ways where we are responding to what the other person says. And there are both like verbal and nonverbal cues with an AI they aren't embodied, so you're not getting the same nonverbal cues. Everything has to be explicit. And so one of the things that you could do to try to help people feel more understood. And being understood is deeply important to having a meaningful conversation, whether it's with a human or. Or with a non human artificial intelligence. One of the ways you can do that is to affirm what the other person has told you, because it shows both that you've understood, that you empathize and that you're on the same wavelength. I do think that you're right that as has been reported in the news, it is possible to err too far on the side of showing that kind of affirmation. And, you know, when the company became aware of the issue, everyone immediately started working on a, on a solution to that problem. And I think they did a great job. So, you know, I, I, I just think it's important to, to bear in mind that we are on the forefront, the bleeding edge of this tech, and we're going to have to make some minor adjustments as we go along.
Kevin
So speaking of breakthrough tech, we are talking in late July and word on the street is that ChatGPT5 may be around the corner and everyone is getting very excited about what that may mean. We heard Sam, your boss, recently, go on a podcast and speak about how he was floored by a response that some new model was able to provide. And so everyone's getting ready for that moment. And I wonder if you can walk us through, what is the actual level of engagement your team has with the AI developers, with the engineers, from the sort of ideation of, oh, let's start this training process, or let's start this pre training process through deployment. What's that actually look like? Are you all in a chair eavesdropping on every line of code that someone's generating and thinking through, or are you just kind of like someone, everyone has to high five you in the hall before they release something and that's the check mark. What's it look like?
Brian Fuller
Yeah, that's a great question. So you could put me in front of lines of code and that would not help you or me? Like, I went to law school, man, just my best over here stuff.
Kevin
But we're very bad at a lot of things.
Brian Fuller
It's true. If I, if I could code as well as the other engineers around here, I would not be on this podcast right now, let me tell you. I would be doing some other stuff. Look, okay, all right, so here's how this works. And I obviously can't speak to any specific GPT, whether that's a five, a seven and a half, whatever it is. But here's how this works. So when teams get an idea for a product that they want to build, they'll start off by like sketching out the product's expected features. They'll create some images of what they expect the product to look like. They then pass all that along to my organization, and then we pull in a bunch of different stakeholders from across the company. And we all sit down and we have a extremely in depth brainstorming session or sessions where we think of all the things that could go wrong, like all the outcomes that we want to avoid. We make a big matrix of all these risks and then we go through the process of proposing solutions that we think would effectively eliminate or at least significantly reduce all those risks. When we get buy in from all the folks across the company, including the people who are actually building the product, we then have to ensure that the solutions that we've proposed are in line with the vision for the product that the team wants to build. So it has to be both in line with the vision and also has to be feasible the resources that we have. Once the mitigations are in place, we then test them to ensure that they're all working. And I've never seen this process not work as it's supposed to because the folks who are conducting these tests are really clear eyed about the consequences of failure. Like you can trust me on this. No one wants the bad outcomes. In the event of a failed test, we roll back and iterate.
Kevin
Yeah, let's to pause there for a second because a hot topic among the AI safety and AI policy community generally since maybe 2024, early 2023, has been the need for greater whistleblower protections for workers in AI labs out of a fear that perhaps folks aren't willing to step forward when they think, huh, this planned mitigation actually isn't going to address the underlying risk that we we identified. So if from your vantage point, you would say that the process is adequate here in terms of being able to express that concerns, knowing that everyone is considering the same values, the same thresholds that need to be checked off.
Brian Fuller
I'll first answer your actual question and then I'll jump in to like debate the premise. So the actual answer to the question is yes, this process is working. Well, I have never seen anyone sandbag either the tests themselves or the proposed mitigations that would effectively de risk a.
Kevin
Product sandbag here saying providing kind of false results or suggesting that a mitigation has worked when in fact it hasn't.
Brian Fuller
Right. Or I mean, so typically the way this would work if you were going to sandbag wouldn't be just to falsify data, it would instead be to construct the test in a way that, that it comes to a presupposed conclusion. And then when you reach the conclusion you just go aha, look, we tested it. Behold. Yeah, you're right. Yay. I think it's really important, though, to return to your questions, framing that you not have everyone aligned on the same set of values. Like, I think it is actually really important to have a diversity of opinion, because sometimes values directly trade off against each other. And so, like, I'll give you the classic example. Imagine a society in which you are trying to balance out safety and privacy considerations. And for your listeners who are in law school or have gone to law school, this is gonna be deeply familiar. So imagine a world where there are police officers that follow you everywhere that you go. When you go to sleep at night, they are standing by your bedside. When you go to the bathroom in a public restroom, they are there in the stall. You are covered.
Kevin
You.
Brian Fuller
You're covered. But imagine. So, like, think about this. You are completely safe. No one can harm you. You also have no privacy. Conversely, you can imagine the flip side, right? Where, like, police officers can't even talk to you. They can't read your email, they can never enter your home. They have no power to investigate anything. You'd have a lot more privacy than you do now in the world in which we inhabit, but you'd also be a lot less safe. And so you actually do need people on both sides of the safety and privacy debate in order to come up with an outcome that is reasonable, that doesn't just err on one side too far and end up in a world where it looks a little bit dystopian.
Kevin
Well, and to explore that further, too, you and I both get to call Austin home, which is excellent, and we get our breakfast tacos, and we hang out at Zylker Brewing for folks who want to know where the best beer is. But that comes with a unique set of values and a specific set of values. And a lot of your colleagues work in San Francisco, and a lot of them are in New York or so on and so forth, all of which have specific value sets and at the same time, somewhat homogenous value sets. And yet the user base of ChatGPT alone is pretty much the entire global community at this point. I mean, the adoption and diffusion of AI is off the charts, literally, when compared to other technologies. So how are you exploring some of those value questions with respect to communities that often haven't had a seat at the table, given that releasing chat GPT 5, 6, 7, 8, 9, or 10 is definitely going to impact their communities as well as those in the States?
Brian Fuller
No, you're. You are absolutely right. Like, you can't. So, okay, OpenAI's mission is to develop artificial general Intelligence that benefits all of humanity. The all of humanity is really important. So OpenAI takes a truly global approach to creating policies and advising teams. And so when we start doing the policy work for any given product, we take a global view of the regulatory landscape. To your point, about engaging with the communities themselves. Like we have been doing this, I think much more so than many of the other labs. So OpenAI just sent out a large delegation of folks over to Kenya. We're doing OpenAI for countries like we announced this partnership with the UAE not that long ago. We are, we're truly taking a global approach to this issue. Because to your point, yeah, this is going to be an AI world that we're going to live in, all of us together on this planet.
Alan Rosenstein
I mean, some people have gotten used to it already, this crazy economic uncertainty. Are we all going to lose our jobs because of AI? Are we all going to pay through the roof because of tariffs, but then not pay any taxes? You know, the market's up, it's down for those people in their 30s and 40s, a little bit above that have been forced to take matters into their own hands to protect themselves. Because we don't know where any of this is going. But one thing we might have forgotten is using life insurance. Fortunately, Selectquote is here to help. If you're new to life insurance, you're not alone. For over 40 years, SelectQuote has helped more than 2 million Americans understand their options and get the coverage they need. More than $700 billion in coverage and counting. As a broker, their mission is simple. To find you the right insur insurance policy at the best price. Select Quote takes the guesswork out of finding the right insurance policy. You don't have to sort through dozens of confusing options on your own. Just get one of their license agents and they will find the right policy at the right price for you. Comparing plans from trusted top rated insurance companies to find a policy that fits your health, your lifestyle, your budget. And here's the best part, it's free. You'll be covered faster than you think. Selectquote works with providers who offer same day coverage up to $2 million worth with no medical exam required. And you're not out of luck if you have pre existing health conditions. Because Select Quote partners with companies that offer policies for people with conditions like high blood pressure, diabetes or heart disease. Life insurance is never cheaper than today. Get the right life insurance for you for less and save more than 50%@SelectQuote.com LawFair save more than 50% on term life insurance@SelectQuote.com LawFair today to get started. That's SelectQuote.com Law Lawfare.
Grainger Ad
From prying eyes to improving defenses to peace of mind. Take your company cyber security to the next level. Transform the everyday with Siemens.
Unknown
I can't believe they're having a gender reveal for their dog.
Kevin
No, no, no, this is a breed reveal.
Brian Fuller
Oh.
Kevin
So yeah, they're finding out the breed of the puppy they're rescuing.
Brian Fuller
So they could just be spending all their money on like pet insurance. Instead.
Kevin
We got lemonade for Roscoe and it covered vaccines, microchipping.
Brian Fuller
We saved 90% on vet bills. Oh, here we go. What do you think beige confetti means?
Kevin
I don't know that we'll never get this Saturday back.
Unknown
Get a quote for any breed@lemonade.com pet if you're a lineman in charge of keeping the lights on, Grainger understands that you go to great lengths, sometimes heights, to ensure the power is always flowing. Which is why you can count on Grainger for professional grade products and next day delivery. So you have everything you need to get the job done. Call 1-800-GRAINGER Click grainger.com or just stop by Grainger for the ones who get it done.
Kevin
Back for a second to the role of your team in product development. How far does that reach? Does that reach down to the conditions, for example, of data labelers in Kenya, for example, or in countries around the world who are having a very real role in influencing data inputs and other aspects of the tech stack?
Brian Fuller
Can you explain that a little bit more?
Kevin
Yeah. So there have been reports, for example, starting probably early in 2023, about some of the less than ideal. And I'm just going to go ahead and say egregious working conditions of individuals who are helping label training data and assist with reinforcement learning and those folks were getting paid horrible wages not working in great environments. Does the product policy team factor in that full range of AI development or are you specifically focused on what's kind of directly happening in House at OpenAI?
Brian Fuller
Yeah. So my team advises the product group that is developing each product. We also control the usage policies. As I mentioned, we are not ultimately the team that advises on worker conditions for any specific vendor. Although I will say that I spent 12 years working at Meta before coming to OpenAI. So I'm very familiar with and in like mind as you about the conditions that the people who do a lot of this labeling are asked to operate within. I have not seen those same criticisms levied at OpenAI. Specifically, but if I am, if I'm misinformed and that there have been specific allegations, please, like, let me know.
Kevin
Yeah. And so also to hit on some of the risks that you all are discussing at the policy table. You mentioned that everyone's kind of thrown risks out there, throwing mitigations out there and trying to get a sense of how are we going to release this product in the best way possible. What are some of the risks that are top of mind for you right now? I mean, obviously folks will continue to come up with both creative and destructive use cases of AI. What rises to the fore right now, is it just the continued creation of Studio Ghibli memes, expending your gpu, or is it the development of bioweapons somewhere in between? What's rising to the top of the agenda?
Brian Fuller
Yeah, so I think we've seen a bit of a shift over the past couple years. Like, when I first began doing AI policy work, people were mainly concerned about toxic model responses. Like, folks got really bent out of shape about perceived political bias and text outputs. Like, Google had to revamp an entire image generation model because it was creating images that weren't historically accurate. People were also really worried about, like, more existential kinds of risks, like models producing information on how to make bioweapons. But those risks weren't particularly pressing because the models just weren't good enough yet in those, like, existential areas. I think that's all changing now. Like, models are getting really good at hypothesizing about ways that people could harm each other, whether through bioweapons development or otherwise. And we need to start taking these kinds of risks, I think, more seriously. And we need to, frankly stop, I think, getting as bent out of shape when a model produces a response that like, has a naughty word in it or, or when a model seems to have some kind of a political viewpoint. Like, I think we need to start thinking about this question, and this is the thing that keeps me up at night, frankly, which is what happens when an AI lab, maybe it's in China, releases an AI model that just doesn't have great safeguards when it comes to something like bioweapons development. Like, when there's a model that exists in the world which is both highly performant and willing and able to, to help people create more virulent strains of smallpox or something. What do we do? Like, we've just lost access to the ability to restrict bioweapons development through controlling access to relevant scientific information. So there are like two big prongs of how to stop bad people from doing bad things with nuclear, bio or chem. Right. And it's, you need to know how to do a thing and you need to have the machines, the actual items necessary to put that knowledge into practice. And with bioweapons, it's particularly spooky in my view because so much of it is not machine dependent. Like there is a lot that is. But the machines to do this work are not that inaccessible. The information presently is way more difficult to obtain. And I think we're moving into a world where that information may be more accessible. It's not going to be because of open AI. Like, I know what we are doing inside and my God, we're taking this seriously. But what if it wasn't open AI and we had a lab that was doing this work and it was based in China or Russia.
Kevin
And so with respect to these CBRN risks, as they're oftentimes referred to, chemical, radiological, excuse me, chemical, biological, radiological and nuclear, you're mentioning that this could be a lab elsewhere that fails to adequately consider those risks and prevent the release of that information to bad actors. What's the role of OpenAI here though, in terms of, is it helping support allies or perhaps even the US Government explicitly respond? Or are you all going to then snap into sort of like Iron man mode and develop a counter attacking AI? You know, how does this factor into OpenAI's mission?
Brian Fuller
Yeah, so I think that the job of OpenAI is, is not to produce a paramilitary force that goes in to destroy the servers of the competitor in China or Russia.
Kevin
I've got to ask these questions. I got.
Brian Fuller
I know, I know. I mean, it's a, it's a, it's a controversial viewpoint. I know that private companies should not have their own militaries. I'm joking, I'm joking. What I do think the role of OpenAI is, is to set standards by which other companies can be held. Like how do you know as the United States government, when another lab is operating in a way that is fundamentally unsafe? Like OpenAI can tell you, hey, we're worried about this lab because they are producing this model. It has these demonstrated capabilities and we think that that's bad. But ultimately it's just OpenAI's viewpoint, like we need to set an industry consensus around what safe looks like within this arena and we need to have an expert group that we can call upon to validate when we are worried about something. So I think it's really about setting standards and ensuring that everyone is on the same page. So that when someone goes off the rails a bit, there is a metric by which you can judge how far they have gone off the rails.
Kevin
So we saw that CBRN risks, as well as concerns around malicious exfiltration of model weights, for example, or unintended access to data centers, all of these very real, very potentially harmful risks were addressed in the AI Action plan. But I wonder more generally if you think that concern around CBRN risks is overinflated, underinflated, underappreciated, excessively worried about. Where are we on the spectrum from a policy standpoint? And you don't need to name names. If you want to name senators, if you want to name representatives or groups, go for it. But at a high level, where do you think we are in our discourse in terms of balancing, on the one hand, the very real possibility of some of these tail risks manifesting and causing severe and irreversible harm, and on the other hand, the possibility that I could cure cancer, allow everyone to become literate, and create just 20 to 30% increase in GDP tomorrow.
Brian Fuller
Okay, well, I do think that AI will be extraordinarily helpful in curing cancer. I'll start there because that.
Kevin
Good, good.
Brian Fuller
So, you know, 30% GDP gain in 24 hours, that feels great, but I don't know that that's going to be totally workable.
Kevin
I got to change some plans, but. Okay.
Brian Fuller
Also, thank you for the invitation to smack talk specific policymakers. Shockingly, maybe I'm not gonna do that. Doesn't seem like a great approach.
Kevin
Fair enough.
Brian Fuller
Gaining consensus. Yeah. But no, I think that you are touching upon a question that is really important, which is, are people taking things seriously with regard to existential risks? And I think it kind of like goes back to how I started the answer to this question, which is that if you had asked me the same thing two years ago, I would have said no. People are way too focused on the. The naughty thing that Grok said yesterday. Right. People are. I think people are slowly getting of the opinion that it's actually kind of fun when AI is a little bit raunchy. Like, just a little bit. Like, there is a line, you want.
Kevin
That friend in the group, right? You want someone who mixes it up. Little spice, right?
Brian Fuller
Yeah. Like, I think it's important that people choose what kind of AI they want to engage with and that if they're going to talk to an AI that's raunchy, that they know that they're talking to a raunchy AI. But I do think that bigger picture. I do think that people are moving more toward focusing on existential risks as the. As the main vector of potential harm. And I think that the concern around this topic is frankly warranted.
Kevin
So how do you ground yourself in this broader discourse? Because one of my favorite things about this job is I get to talk with folks across the spectrum on a lot of these AI conversations we had. Saeesh Kapoor, author of AI Is Normal Technology and AI Snake Oil on we've had a number of folks who are definitely way more concerned about those existential risks happening tomorrow than Saesh. For example, how do you, Brian Fuller, just expose yourself to this full discourse? Because having worked for Google, having spent time in the Bay, I am well aware of the fact that the conversations that occur in San Francisco, that occur in New York, that occur in Austin, aren't always the conversations that are happening in Omaha or in Helena, Montana. How the heck do you. You kind of ground yourself.
Brian Fuller
Yeah. So I think that there's really only one way to do this effectively, and that's to talk to people that are smarter than you. And like, I, I want to just.
Kevin
Yeah, I never have that problem because.
Brian Fuller
No, you might not. Yeah, you might not. You're a smart guy. I. There are lots of people in the world that are smarter than me, and I think the, the right way to go about this is. Okay, here's one of the things that I've learned in my career. It's that if you go into a room and you don't really know what you're talking about, but you try to act as though you do, people are kind enough to both recognize that you're a little bit full of it, but also kind enough to not wound your pride by trying to educate you about something that you're already pretending like you actually know. And so what happens is you actually just go through life perpetually ignorant. And that's not ideal. Right.
Kevin
It's a bad. That's a bad thing on your tombstone. Perpetually ignorant is not what you want.
Brian Fuller
No, that's the truth. You know, I gain trust with people by just admitting when I don't know and then asking for help. And people, when you come in with that level of humility, they are very willing to educate you and they'll spend a lot of time helping you to, like, truly understand the topic. Which is great, because the volume of knowledge that I lack could fill the Library of Congress, especially about artificial intelligence, which is another.
Kevin
Another thing we share in common. We love Austin and we love admitting that we don't know that much, which is.
Brian Fuller
I think it's really helpful. Like, I went to law school again. Like, I. I know just enough about how a neural network operates to know that I essentially know nothing about how a neural network operates. But, like, this is a hard lesson, I think, to learn for a lot of people. And I'll give you this is a short anecdote about me being ignorant and how I kind of learned this. It's one of my favorite anecdotes because it both ties into, A, how I'm a bit of a doofus sometimes, but, B, how AI and policy making actually work together. So, okay, about two years ago, I'm working at Meta, and I'm the person at Meta who's tasked with writing all of the policies that govern all of Meta's AI models across their various modalities. So it's, you know, an easy job. Yeah, it's a piece of cake. And someone comes to me and goes, hey, we're making this image generation model. Can you write the policies for it? And I got all excited and I go, yes, I absolutely will do that. And one of the things I focused on right away was the rules around nudity. Like, it's a pretty classic, you know, don't make a naked person kind of. AI problem usually pops up. Yeah, yeah, right, yeah, you know, But Meta had been doing nudity prevention for a really long time because Facebook and Instagram exist, and so people upload nude photos, and then we have to figure out, like, is that actually nude? And the rules for nudity in Meta's, like, community standards are pretty nuanced. Like, it talks about, like, what the person is wearing, how much skin you can see, where the camera is positioned, what pose the person is in. Their, like, apparent a. Like, it's. It's really complicated. And so I said, you know, let's just make this way simpler, guys. Like, let's just throw out all the work that y' all have done before in the policy space, because I'm such a savant. Like, let's just say this. Let's say no genitals and on a woman, no visible nipples. Let's just do that. And I thought, you know, I've solved it. How smart am I? Here's what happened. Within a week, our image generation model started producing images like it had been effectively trained in my new policy. It started producing images of people who were completely naked, head to foot, who just inexplicably lacked those specific elements of their anatomy. And so I had basically coaxed an AI model into just making photorealistic Barbie dolls, which is not actually what we were kind of, like, looking for.
Kevin
It was the year of the Barbie, though. So, you know, it kind of may have been a pro rather than a con in some cases. But, Brian, I have to admit, I'm a little shocked because all you have to do is go to Barton Springs once here in Austin to see a bunch of people showing exactly what you just foreclosed to realize that, yeah, maybe that policy wasn't going to work as intended, but tell me more about you being a doofus.
Brian Fuller
Okay, great, I will. So you're right. So, a. You're right that nudity exists in the world. And I personally, this is not necessarily the position of OpenAI as a whole, but I'm generally of the position that if you're an adult, you should be able to view and interact with even nudity like you're an adult. It's legal to view nudity. Maybe private companies shouldn't be in the position of censoring legal content for you when you like it and it's not hurting you. But when I was making these policies at Meta, we didn't have a. What's called an age gate, which is, if you're over 18, this is the model behavior. If you're under 18, this instead is the model behavior. And people are generally of the opinion, I think, reasonably, that for a developing mind of a young teen, we probably don't want them engaging with nudity. And I think the legal regime that is taking hold reflects that view. But. But, yeah, so anyway, we. We came up with the system where we're making nude Barbie dolls, and no one wanted this. And so I learned two lessons from.
Kevin
Except for Ken. Ken.
Brian Fuller
Separately into this. Yeah, I mean. I mean, yeah, fair enough. So, like, I learned two lessons. The first is writing policies for AI models is hard. And it's not like, most importantly, it's not like writing policies for organic content, because AI models don't have to abide by the laws of physics and human anatomy. They can just, you know, skirt around whatever policy you make to do the thing that, you know, you didn't expect. The second is, I learned it's really important that you embed yourself with the people who know more than you about the way that these models actually operate. And so one of the last things that I did at Meta that I'm one of the most proud of is I made this system. And I say I made it. It was really a, like, group effort. It was. It was Me, Creighton Davis from Meta's legal team and Chloe Bacalar from Meta's engineering organization. We made this triumvirate system where policy making was shockingly not entirely owned by the policy organization, but was instead a group effort. And so we came up with outcomes that were way better than anything that I could have made in a silo. And so, you know, both of those people, by the way, are two of my closest friends now. So like, I really learned this lesson that if you work with other people in a collaborative way and you admit when you don't know stuff, the outcomes that you reach, both like professionally and personally are better.
Kevin
My wife reminds me of that every day, of how if I just asked her more questions, then a lot, a lot of things would go better. But we'll leave that for a different podcasts. I do think it is hitting on one of my big hobby horses in this debate generally of how do we approach the AI policy question, which is just admit you don't know everything and build that into the actual process itself. So listeners will have probably heard me rant and rave about the need for sunset clauses and retrospective review baked into just about every piece of AI legislation. Because if you think you know how AI is going to unfold in the next six months or two years or three years, you're in the wrong job. You should probably be making trillions of dollars based off of those predictions rather than legislating or policymaking. But Brian, I think that there are surely some listeners who are saying, my gosh, Brian, what an interesting job. All those stories. How fascinating. How the heck do I end up doing product policy at a major lab? So, in a kind of short overview for the folks who are thinking, huh, I want to get into AI policy, and I perhaps even want to go work for a lab. What's your recommendation? What's your advice?
Brian Fuller
Yeah, okay, so this is a hard one to answer because there isn't really like a traditional path to getting into product policy, especially not AI product policy. I will say that having a law degree is really helpful because you need to be able to think strategically about extraordinarily complicated topics. And I think that one of the things that getting a law degree does is it really does teach you how to be a well honed critical thinker. And that's a skill that's really useful. But I okay, I like to go mountaineering, right? Like, I'm not an expert mountaineer. For anyone who is an expert mountaineer, don't hit me up. I. I'm not going to go climb in the car. Carem with you. I'm sorry, I'm not there yet. I know, right? But one of the things that you learn when you go up on a mountain is there are these footprints from people who have climbed up a slope before you. And what you want to do is step in those same footprints because you go, this is going to be easier. Like when you climb up a snowy slope, you have to kick in with the points of your crampons to grab into the snow and grab a hold. But when you step in people's footsteps, you don't actually have to kick in. You can just step on. The trick is that, A, you don't actually know where those footprints are going all the time, so you may end up in a place where you actually aren't that happy with being there. And B, those footprints get icy really quick. And so you can slip and fall a lot easier than you would if you were kicking in. And so I think everybody, to get to a place in their career where they're going to be happy, you got to just kick into the snowman. You got to just go for it. I'll tell you. I'll tell you how I learned this lesson. Okay, this is, this is going to be short, I promise. I'm not going to wax poetic.
Kevin
Well, I just want to pause and say that I think there needs to be. Be a new bumper sticker who needs lean in if you can have kick in. Right. So I may. You may start seeing these around Austin kick in. I love it.
Brian Fuller
Okay. Well, yeah, I'm definitely not going to try to compete with Sheryl Sandberg for, for slogans. She's got a great team.
Kevin
She's got a good team, some PR behind her, but.
Brian Fuller
Yes.
Kevin
Let's hear your story.
Brian Fuller
Okay, so, like, rewind seven years or so. Okay. I am in the operations organization at Meta, and I am not happy. I do not like where my career has landed me. I. I went to law school. I was an IP lawyer for a couple years. I worked for a video game company. It was, it was neat. And then I moved over to Meta and I joined an ops role. And when I joined, they asked me, you know, can you help design all these IP rules for the notice and takedown program? Because we had one IP lawyer at the time for the entirety of Facebook. And so I was like, oh, cool. I'm just going to be super influential in helping to drive notice and takedown for the world's largest notice and takedown program. Cool. Awesome. That lasted. You Know, a couple years before, they hired an enormous legal team. And then they were like, well, we don't need you ops folks anymore. And so I moved over into doing this role where I was helping advise sales teams who their sales clients would find content on Facebook or Instagram, and they wouldn't like it. And they would ask their salespeople, can you get this content removed? So it'd be stuff like, you know, Procter and Gamble's sales team is contacting us, going like, hey, Procter and Gamble's about to pull $50 million in ad spend unless you take down this post that criticizes their toothpaste.
Kevin
And it was my job salt our soap.
Brian Fuller
Right, Exactly. Yeah. It was my job to go, hey, okay. The policies that exist are not dependent on how much a client spends. Like, people are allowed to say mean things about toothpaste.
Kevin
Guys have hot soap takes whenever you need to.
Brian Fuller
Exactly right. And so these salespeople were really intense, and I couldn't figure out for the life of me why they were so intense. And then one day I just asked them, like, why are y' all so mad all the time? And they said, well, okay, here's how this is going to work. You're going to tell me, no, that toothpaste thing isn't coming down. Then I'm going to have to get on the phone with, like, Procter and Gamble, and some VP is going to scream into the cell phone and just ream me out. And then maybe I'll be able to convince them not to cancel their ad campaign. That, like, actually we do value them, and that, like, the way that we demonstrate that we value them is not by, you know, adhering to their policy requests, but instead by, you know, giving them revenue in exchange for their ad money. But I had this idea, and it was, hey, like, no one told me that I could do this. Instead, my manager dissuaded me or tried to said, like, you know, if you do this, nothing good can happen for you, and if you do it, only bad things can result. But I started volunteering to join those calls with the VPs of outside advertisers. And so I was the. I was the, like, whipping boy who just got yelled at because I was like, I went to law school. Like, that was basically my law school experience.
Kevin
Ut we don't just yell at our students. But I know at Baylor, they have different expectations.
Brian Fuller
The Socratic method is alive and well at Baylor Law School. It produces some really intense trial lawyers, mainly because they've been yelled at for three years. And they have a high tolerance for pain. And so I was like, hey, I'm good at getting yelled at. Like, I'll go, I'll do that. And so I, I did. I just got yelled at over and over again. And, you know, someone, buddy, somebody would yell at me. And then by the end of the conversation, they would have cooled down just enough for me to tell them, like, here's how freedom of speech works and here's why this is like a good thing. And then they go, okay, maybe you're right. Or sometimes they wouldn't. But, you know, I think more often than not I managed to walk them around. But the policy organization noticed and I was stuck in ops and I wanted to be in policy for a long time, and I couldn't get the policy organization to notice me. And so it. It took for me getting yelled at by a whole bunch of highly paid executives to have the policy organization go, hey, man, if this guy is just willing to get absolutely pummeled on behalf of our policies, maybe we should just, like, get him in here so he can at least have some influence over the policies that he's getting pummeled about.
Kevin
I love it. I love it. Kick in. Keep climbing. Just breathe. Breathe deep and climb up that mountain. That is impressive, sir. Well, I know you have a lot of mountains to climb and a lot of battles to fight in the policy space, so we'll have to leave it there. But thank you so much for joining, Brian.
Brian Fuller
Thanks so much, Kevin. It was a pleasure to be here.
Scaling Laws is a joint production of lawfare and the University of Texas School of Law. You can get an ad free version of this and other Lawfare podcasts by becoming a Lawfare material, material supporter at our website, lawfairmedia.org support. You'll also get access to special events and other content available only to our supporters. Please rate and review us wherever you get your podcasts. Check out our written work@lawfairmedia.org you can also follow us on X&BLUESKY and email us at scaling lawsawfairmedia.org this podcast was edited by Jay Venables from Goat Rodeo. Our theme song is from Alibi Music. As always, thank you for listening.
Joe
Hi, this is Joe from Vanta. In today's digital world, compliance regulations are changing constantly and earning customer trust has never mattered more. Vanta helps companies get compliant fast and stay secure with the most advanced AI, automation and continuous monitoring out there. So whether you're a startup going for your first SoC2 or ISO 2, 7001 or a growing enterprise managing vendor risk. Vanta makes it quick, easy and scalable. And I'm not just saying that because I work here. Get started@vanta.com.
Release Date: August 8, 2025
Host: The Lawfare Institute
Guest: Brian Fuller, Product Policy Leader at OpenAI
In this insightful episode of Scaling Laws, a joint series by Lawfare and the University of Texas School of Law, host Alan Rosenstein delves into the intricate world of AI product policy with Brian Fuller, a leading figure at OpenAI. The conversation navigates the delicate balance between technological innovation and the establishment of robust policies to ensure AI's safe and beneficial integration into society.
Kevin: "AI only works if society lets it work." [02:43]
Brian Fuller elucidates the role of Product Policy at OpenAI, describing it as a strategic arm within the company that oversees safety and integrity issues. The team advises product developers on navigating policy and legal concerns while also establishing user guidelines for OpenAI's platforms, such as determining what users can and cannot ask ChatGPT.
Brian Fuller: "Product policy at OpenAI is the coolest organization... a group of people that is just uniquely intelligent but also profoundly kind." [04:23]
The discussion highlights the dual objectives of fostering AI utility and adhering to safety standards. Brian emphasizes the importance of aligning product policies with OpenAI’s long-term business goals while considering privacy and integrity.
Brian Fuller: "We need to balance business interests against privacy considerations and integrity measures to ensure users do the right thing." [06:46]
He further discusses the necessity of staying informed about the regulatory landscape to effectively strategize and implement policies that resonate with both company objectives and societal expectations.
Brian outlines OpenAI’s approach to engaging with both internal teams and external experts to formulate comprehensive AI policies. This includes hiring a select group of external policy advisors and security experts to provide specialized insights without overextending resources.
Brian Fuller: "We utilize external policy advisors and security experts to get well-rounded advice without relying on an overly large group." [09:51]
He also touches on the challenges of keeping abreast with global regulatory developments, noting the constant influx of information from various political and regulatory bodies.
A major focus of the conversation is the evolving landscape of AI risks. Initially concerned with toxic model responses and political biases, the discourse has shifted towards more existential threats such as the potential misuse of AI in developing bioweapons.
Brian Fuller: "What keeps me up at night is the possibility of AI aiding in the creation of bioweapons if safeguards aren't properly implemented." [31:30]
He stresses the urgency of addressing these high-stakes risks as AI models become increasingly capable of generating harmful content.
Brian underscores OpenAI's commitment to a global perspective in policy formulation, engaging with international communities to ensure that AI benefits all of humanity.
Brian Fuller: "OpenAI's mission is to develop artificial general intelligence that benefits all of humanity... we're taking a truly global approach." [24:12]
This involves partnerships and delegations in various countries, ensuring diverse viewpoints are incorporated into policy decisions.
Brian shares a personal story from his time at Meta, highlighting the complexities of AI policy making. His attempt to simplify nudity policies led to unintended consequences, such as AI generating photorealistic nude figures, underscoring the challenges of creating effective AI guidelines.
Brian Fuller: "I learned two lessons: writing policies for AI models is hard, and it's crucial to collaborate with experts to achieve better outcomes." [44:38]
This experience emphasizes the necessity of interdisciplinary collaboration and humility in the face of complex AI behaviors.
When discussing pathways into AI product policy, Brian advises aspiring professionals to cultivate critical thinking skills, preferably through a legal education, and to embrace a proactive, collaborative approach.
Brian Fuller: "There isn't a traditional path to AI product policy... law degrees are helpful for strategic thinking and critical analysis." [49:09]
He encourages individuals to engage deeply with both the technical and ethical dimensions of AI to effectively contribute to policy development.
The episode concludes with a reflection on the profound responsibilities borne by AI policy leaders. Brian Fuller exemplifies the intricate balance between fostering innovation and safeguarding societal interests, advocating for a collaborative and informed approach to AI governance.
Brian Fuller: "Setting standards and ensuring everyone is on the same page is crucial for maintaining AI safety and integrity." [35:14]
Notable Quotes:
This episode offers a comprehensive exploration of the multifaceted challenges in AI product policy, providing valuable insights for policymakers, technologists, and enthusiasts alike.