IH.

FIELD NOTES / AI

The Channel Isn’t the Interesting Part. The Searcher Is.

ihaq · · 8 min read

Human brain and artificial neural network compared: shared signal processing and learning, different mechanisms, and unresolved AI consciousness.
A conceptual comparison. Download the diagram.

I keep coming back to a strange possibility: we may build something more intelligent than ourselves before we understand why we are conscious.

A brain and a GPU are both physical systems. One works through living cells, chemistry and electrical signals; the other through silicon and transistors. Neither a neuron nor a transistor explains intelligence on its own. The organization matters, as do the ways the system changes through learning.

The resemblance is useful, but it only takes me so far. A brain is not simply a computer made of different material, and an artificial neural network is not a detailed copy of a brain. What holds my attention is the distance between processing information and experiencing it.

I see color. I feel pain. I have the experience of being me. We can study the brain activity associated with those experiences, yet we still lack an agreed explanation of why there should be an experience at all.

Quantum theories of consciousness interest me, but interest is not evidence. The fact that brains obey quantum physics does not establish that they perform quantum computation, or that such computation explains awareness.

For the future of AI, though, we may not need to settle that question first. A system could become extraordinarily capable while we remain unsure whether it experiences anything.

Intelligence, with permission to act

We tend to bundle intelligence, consciousness and agency together because we encounter them together in ourselves. When I pursue something, I also feel curiosity, impatience or hope. It is easy to carry that picture over to machines.

But a system need not feel curiosity to search for an answer. It need not feel ambition to keep working toward an objective. Harm does not require hatred, either. A badly chosen objective, pursued effectively, can be enough.

The combination I find more immediately consequential is intelligence, agency, autonomy and access. I use these as practical distinctions: intelligence concerns what a system can figure out; agency, whether it can pursue an objective over time; autonomy, how much it can do without asking; and access, which parts of the world it can affect.

A system that can reason, use tools, observe results and revise its approach can already matter a great deal. Whether there is anything it feels like to be that system is a separate question.

That distinction was on my mind when I heard Noam Brown discuss isolation in his conversation with Dwarkesh Patel. His example involved something I would not normally think of as a communication device: a temperature sensor.

A very slow conversation through heat

An air gap removes ordinary network connections. It is a strong security measure, but it does not remove a computer from the physical world.

In 2015, Mordechai Guri, Matan Monitz, Yisroel Mirski and Yuval Elovici demonstrated BitWhisper. Two nearby computers, both already compromised, exchanged information through changes in heat and readings from their built-in temperature sensors. Their experiments reported distances of up to roughly 40 centimeters and rates of about one to eight bits per hour.

Those limitations matter. This was a constrained laboratory demonstration, not evidence of an AI independently escaping containment. It required suitably positioned machines and software on both ends. At that speed, moving a large file would be impractical, let alone an entire AI model.

Still, a short signal can be useful. If two systems already share a plan and a convention, a single bit might tell one of them to proceed or wait. Without that prior context, the same bit may mean nothing.

What interests me is therefore less the volume of information than the smallest signal a particular coordination task requires.

Brown’s example prompted a broader question for me: what happens when a system can search for possibilities its designers did not anticipate?

The searcher inside the boundary

Someone had to notice that heat could carry a message. The hardware was already there; the communication channel was an unintended use of it.

I find that easy to appreciate as a builder. A component has a purpose on the drawing, but its behavior does not end there. It draws power, warms nearby parts, responds to its surroundings. Working across hardware and software makes the distance between a diagram and a working system hard to ignore.

Now imagine a capable AI with enough visibility and control to investigate its surroundings. It might ask what it can observe, what it can change, and whether changing one thing produces a measurable effect elsewhere. Given the necessary tools, time and feedback, it could test those relationships.

That is a possibility to take seriously, not a claim that intelligence makes every boundary porous. A system cannot use a sensor it cannot read, control hardware it cannot reach, or invent a physical connection where none is available. Good isolation imposes real constraints.

The difficulty is knowing which constraints actually hold. A security design has to account for the environment and for the capabilities of whatever is operating inside it. Defending against a fixed list of known behaviors is different from evaluating a system that can experiment and adapt.

The thermal channel is one example. The search for an overlooked possibility is the more general concern.

Useful systems need carefully chosen connections

I do not think this makes containment pointless. Nor does it mean that every AI must have broad access to be useful. An isolated system can still produce valuable analysis through a reviewed output channel.

But many of the uses that excite me involve action. An AI scientist might propose an experiment, send a permitted instruction to laboratory equipment, examine the results and decide what to investigate next. An engineering system might design a component, run simulations and revise it after testing.

There is enormous promise in shortening those cycles. Some work could run in parallel; some delays could disappear. Other limits would remain: an experiment takes the time it takes, equipment fails, and a promising result still needs validation. Faster reasoning is not the same as instant science.

Even with those limits, I want us to build these systems. I want to see what they can help us discover in biology, materials, energy and physics.

Each useful connection, though, creates a decision about authority. Permission to analyze an experiment is different from permission to run it. Permission to recommend a purchase is different from permission to spend money. Access to one instrument should not quietly become access to the entire laboratory.

For me, this is where the abstract discussion becomes an engineering problem: how do we give a system enough freedom to be useful while keeping the scope of that freedom explicit?

Authority has to be enforceable

A request to “stay within these limits” is not the same as a limit enforced by the system receiving an action.

I want to know who authorized the action, which resources that authorization covers, how long it lasts, and whether it can be delegated. I also want a record of what happened. If permission is withdrawn, the systems carrying out the work need to honor that withdrawal.

Revocation has limits of its own. Stopping the next action cannot undo money already spent or reverse a physical experiment. Some decisions need approval before execution, and some activities need independent interlocks regardless of how capable the AI becomes.

This is also part of why I am building Delegus.ai. I am interested in how a receiving service can verify an agent’s delegated authority. That addresses one piece of the problem. Authorization alone does not ensure that an objective is sensible, an action is safe, or a system is aligned with human interests.

My broader principle is that control should improve at least as quickly as capability. As we let systems work for longer, use more tools and act with less supervision, we should also get better at observing them, limiting their reach and stopping them.

I would be uncomfortable with the opposite bargain: rapidly expanding what a system can do while assuming that control will catch up later.

Back to the question of consciousness

After all this, I still return to the mystery that started it.

Perhaps consciousness depends on features of biology we do not yet understand. Perhaps some artificial systems could support it. I do not know, and fluency alone would not persuade me either way.

We may encounter a machine that can solve problems beyond us while remaining unable to answer whether it experiences its own work. That would be remarkable—and it would leave us with immediate responsibilities, whatever the eventual answer about consciousness.

What can the system do? What can it access? Who gave it authority, and what happens when that authority ends?

Those questions do not diminish my excitement about AI. They are part of taking its potential seriously. I want intelligence that extends what people can accomplish, with boundaries we can understand and enforce.

The channel is what caught my attention. The intelligence searching for one is what stayed with me.

Back to writing