‹ BackHN Continuity

Thread

Prompts aren’t Real

118 points · 57 comments · mcfunley

  1. cortesoft · · focus · HN ↗
    I hope the future of AI isn't this sort, where companies provide the user/customer with an interface to an AI that can do things for the user... I would much prefer that companies instead provide an interface FOR an AI, and the user brings their own AI which connects to that interface.

    In other words, provide my AI with tools, instead of providing me an AI that uses your tools.

    That way, my AI can bring all the context it needs, and I can bring all of the settings and knowledge about what I want with me. I don't want a fractured world of tons of AIs i interact with where I have to explain all the fundamental information about what I want and how I work every time.

    This also has the benefit of sidestepping the issue the essay is talking about. You provide a consistent tool, and the AI weirdness is not your issue anymore. You don't have to worry about solving for all the weird ways people prompt the AI, or the ways they break.

    1. kennywinker · · focus · HN ↗
      I don’t think that will happen. It sounds good, and I would like it if things operated that way - but from the company perspective how do they, for example, have a tool call that gives the customer a discount, without it getting used when it shouldn’t?

      Companies want ai to replace human customer service decision making, which means it can’t just be an api that an external agent can interact with, because it needs private knowledge of company processes and access to capabilities that are abusable.

      But we’re already at the point where if you manage to talk to a human, mostly you end up speaking to someone with no actual power to resolve your issue - so i think basically the future is just going to suck

      1. davnicwil · · focus · HN ↗
        > from the company perspective how do they, for example, have a tool call that gives the customer a discount, without it getting used when it shouldn’t?

        I might be misunderstanding your point but I think you're in agreement with the gp, as in they are arguing for a locked down interface behind which the AI sits, narrowed to use within whatever particular operations the user can access, as opposed to a wide open AI interface with access to any operation (in principle).

        So in your example there's no way to ask the AI for any old discount because the interface for doing so is locked down to just the discounts you can access, although the AI may be able to apply a discount you didn't ask for dynamically, if allowed, to give the customer a better experience.

        Of course both versions can be implemented securely, it's just probably in general a smaller attack surface if you provide a tighter interface first.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.