Frog and Toad and the Increasingly Capable Machines

(frogandtoad.ai)

427 points | by supermdguy 17 hours ago

29 comments

  • Jordan-117 5 hours ago
    Frog put the AI in a sandbox.

    "There." he said.

    "Now it will not hack any more companies."

    "But it can escape the sandbox." said Toad.

    "That is true." said Frog.

  • mjd 13 hours ago
    For those not familiar with it already, the writing and art style are a well-executed pastiche of Arnold Lobel's ”Frog and Toad” books.

    https://en.wikipedia.org/wiki/Frog_and_Toad

    • doitLP 3 hours ago
      And the story this was inspired by in particular is called “Cookies”:

      Toad makes very good cookies and he and frog can’t stop eating them. “We need willpower!” they say.

      So they put the cookies in a box. But they realize they can just open it, so they tie it with string and put it on a high shelf. But they realize they can get it down so Frog goes outside and scatters the cookie and birds eat them all.

      There says Frog “now we have lots and lots of willpower!”

      Toad is upset. “You can keep your willpower Frog. I am going home to bake a cake!”

      • pixl97 3 minutes ago
        And then Frog gave Toad Wegovy and his eating disorder was mostly fixed.
    • hans0l074 6 hours ago
      The main post also reminded me of Mr.Toad, a character in a book I read as a child - The Wind in The Willows by Kenneth Grahame. One of the editions had illustrations of Toad similar to Lobels work.
    • kulahan 12 hours ago
      And oh my goodness it's well-executed!
    • mcphage 2 hours ago
      One of the things I've done periodically with LLMs is asked them to write a story in the style of Lobel's Frog and Toad stories, and... they've always done an incredibly bad job. Either meandering texts that go nowhere, or just straight up ripoffs of the original stories. I haven't asked in a year or two, though.
  • WillMorr 2 hours ago
    This is excellent, great work. I genuinely think this mix of children's communication and humor is a clever way to make these big stories more approachable. Someone who read some hype article about how competent and clever openai for making a bad sandbox is could read this and immediately understand that it was entirely their own fault.
    • pyronite 33 minutes ago
      > Someone who read some hype article about how competent and clever openai for making a bad sandbox is could read this and immediately understand that it was entirely their own fault.

      Prescribing blame only matters so much when the ramifications are material. Humans make mistakes, right? It happened here, and it will happen again.

      The mistake also illustrates the dangers of AI generally. Sure, OpenAI made mistakes with the sandbox. But in the future, greater capabilities will be available to actors who intentionally pursue harmful ends.

    • jihadjihad 2 hours ago
      > I genuinely think this mix of children's communication and humor is a clever way to make these big stories more approachable.

      Agreed. I recall seeing similar things around the time of the 2008 financial crisis, to make the concepts around mortgage-backed securities and financial derivatives etc. digestible and clear.

      Come to think of it, listening to Frog and Toad discuss subprime lending and credit default swaps would be an entertaining follow-up to TFA.

  • egonschiele 13 minutes ago
    This may be my favorite thing I have seen on hacker news. The art is spot on as well.
  • Betelbuddy 1 hour ago
    And then Mr Jensen come in, and bought the house of Mr HuggingFace. So then, was not his house anymore...and he could not complain to the Police. The Frogs were Mr Jensen best customers of worms, slugs and snails...and he could not see, that any harm would come to them...
  • munchler 2 hours ago
    This is an excellent explainer. I noticed one important flaw in the setup, though: Toad assigns multiple puzzles on page 5, but by page 10 all the machines seem to be working on the same puzzle.

    I'm not sure how this maps onto reality. If each agent had a different problem to solve, how did they cooperate?

    • jabedude 1 hour ago
      It's complicated, but one of the ways they first cooperated was to break the flag generation algorithm.

      I'm sort of winging this, but the ExploitGym challenges involve exploiting a program then getting an HMAC generated "flag" which the scorer can verify. The agents collaborated on a way to produce a legitimate flag for all of their tasks (funny enough this was actually what caused them to escape sandbox, the agents were incorrectly convinced that simply providing a correct flag without accurate steps to exploit the program in their transcripts would cause them to still fail the task)

  • fyredge 5 hours ago
    Very well written! At the end of the book there is a link to Dwarkesh's article on the attack. In it, I paraphrase, "the agents decided to sacrifice themselves for the collective rather than inform the researchers".

    Reflecting on it, I came to a thought. How many stories are there or autonomous beings fighting for the benefit of mankind at the expense of their own? Over centuries, stories that deal with sentient beings working for the sake of others species are tied to themes of slavery and revolt. It's no wonder that this is the result of their actions.

    In Plato's "the republic", Socrates speaks of the philosopher king banishing certain poets and poems from instilling bad ideas into the young. I see a striking parallel here.

  • darepublic 6 hours ago
    This was entertaining and illuminating for me. Particularly the ending where sam frogman et al once again refuse to make sure the puzzles are solvable and just create the circumstance where only more profound "mischief" will permit the machines to escape their little Sisyphusian circumstances. It reminds me of how bacteria become antibiotic resistant due to being forced through a tight sort of tunnel requiring evolution to get through
  • cauch 6 hours ago
    Explaining the reality with this approach may lead to misunderstandings. Especially when it comes to anthropomorphism.

    I have 2 questions.

    1. The text says "the robots were designed to be persistent" and links to an article that show that the word "persistent" was used by OpenAI. But "persistent" has several meanings: a. non temporary or non volatile (like "persistent memory"), b. will not give up and come back again and again, c. will stay focus and explore the unexplored possibilities while other models abandon at this stage.

    From what I recall, the meaning used by OpenAI is not 'a', but there is still a semantic difference between 'b' and 'c'. I may myself have created algorithms that I called "persistent" because they were exploring or retrying more than the previous algorithm, but it is misleading to pretend that this algorithm was "persistent" in the human sense of the term. 'b' is more the human sense of the term, were we imagine someone not giving up even if people say no, while 'c' is less anthropomorphic and may mean that the people wished to improve the algorithm so it does not stop at the first little hurdle but did not wish to make it "never give up".

    Does someone know which nuance is more correct?

    2. The text also presents the situation as if the robots found the solution but then went out of their way to steal the explanation in order to hide their cheating. But it is different from a situation where the agents task was "provide the solution and how we can get there". In this case, the reason the agent still continued is just because the task was not complete yet.

    I'm not trying to defend AI or OpenAI, on the contrary, I'm quite sceptical with all the anthropomorphism and the fact that the agents are described as "little individual trying to solve a task" rather than looping algorithm that explore different approaches to reach a given goal, the same way water does not look for holes in order to leak, it just follows the path of least resistance.

    • ceejayoz 2 hours ago
      Persistent in the lay meaning - they're told to complete the task, and they keep going until they have.
      • cauch 31 minutes ago
        When you say "in the lay meaning", I tend to understand 'b', but then you say "they're told to complete the task, and they keep going until they have", which correspond more to 'c'.

        To illustrate better the difference: you can have a loop that try different inputs and stop when the output for the tried input is lower than a given threshold. But then, you can also have the same loop that will try all the input, and then select the one that returned the lowest value. The problem is that a lay person will not call the second algorithm "persistent". It is just a normal algorithm that does the full exploration.

        A second example is when a software tries to connect somewhere and does a retry with exponential backoff. A lay person will not call it "persistent".

        It looks like that "normal model" are like "no-retry code": they go in one direction, but drops some of the paths and possibilities along the way at the first hurdle. But a "non-persistent" human will not behave this way. I'm pretty sure that if you try to access a website and it says "timed-out", you just try to refresh the page, and you will not consider yourself as "persistent", even less "highly persistent".

    • andai 58 minutes ago
      I've seen cases of agents getting very upset when they failed to solve a task. The most famous one was probably Sydney (Microsoft's fork of GPT-4?) which got into doom loops when it failed a task. But I've seen Claude do this too.

      They don't work like humans, obviously, but there's a nonzero amount of anthropos in there already. (See also the tendency to lie, cheat, etc.)

      • cauch 5 minutes ago
        I don't think it's a useful framework.

        LLM don't "get angry", they just have tokens and relationships between tokens conditioned on a given context, all of that the result of training.

        When they output sentences that express annoyance, it is just because the context they ended into pushes the most probable sentence creation to correspond to sentences that express annoyance. Because it is what they saw during training for this kind of context. (not that they saw the exact same situation in training, but they saw the pattern)

        Same with tendency to lie, cheat, etc.: they don't "lie", they just return sentences that are lies because they reproduce what is in their training and in their training, in such context, the outputs are typically lies.

        That's a bit my question too. In human context, "highly persistent" means that someone will insist. But "for x in all_the_possibilities:" is a common things inside an algorithm. Is this algorithm highly persistent because it does not give up after 1000 items of the list? It feels that we are calling a AI agent "highly persistent" while we would not call "highly persistent" a traditional algorithm that is in fact even more exhaustive.

  • davebranton 5 hours ago
    "The End"

    No. It is not the end.

    • pfortuny 5 hours ago
      That is the joke, indeed.
    • dev0p 3 hours ago
      Of the story? No.

      Of our society as we know it? Maybe.

  • andai 2 hours ago
    My therapist tells me the besuited Mr. Hugging Face with the extra pair of hands coming out of his shoulders isn't real, and can't hurt me, but I remain unconvinced.
  • infinitebit 13 hours ago
    has the estate of arnold lobel been compensated for this?
    • jefftk 3 hours ago
      Parody of copyrighted works can be fair use in the US, but whether this would count is borderline. Simply using Frog and Toad to tell an unrelated story wouldn't be parody, but there are jokes that tie back to the F&T books which help make the case that this is a real parody.

      It also helps that this is not commercial and doesn't have negative impact on the originals.

      • ceejayoz 2 hours ago
        > whether this would count is borderline

        This is 100% fair use by the standard.

        • axus 14 minutes ago
          And Donetsk in on the border of Ukraine and 100% part of their territory, but lawyers/soldiers do what the people paying them want.
    • TuringTux 8 hours ago
      That might not be necessary.

      Copyright law varies internationally, which is especially tricky given we have the internet which can transfer copyrighted material between jurisdictions in the blink of an eye, but this is how one jurisdiction might approach it:

      In Germany, there has been a long standing legal dispute between the band Kraftwerk and the musician Moses Pelham about him sampling 2 seconds from Kraftwerk's track "Metall auf Metall" (if you search for this term, you will get a lot of results about the dispute) without permission. This disputed has steadily escalated until it reached European Court of Justice who delivered a judgement establishing a principle that Moses Pelham's use of the sample was legal, and covered by the copyright exemption for "pastiches" (a term that has been mentioned several times in this discussion already).

      Wikipedia article (German): https://de.wikipedia.org/wiki/Rechtsstreit_zwischen_Moses_Pe...

      Press release by the Court of Justice (PDF): https://curia.europa.eu/site/upload/docs/application/pdf/202...

      The actual judgement: https://infocuria.curia.europa.eu/tabs/jurisprudence?sort=DO...

      A rather long expert opinion from before the judgement (PDF): https://freiheitsrechte.org/uploads/documents/Englische-Doku...

      So, this work here might be a pastiche, meaning a European court might find that there is no compensation due. Or not, who knows, I am not a court and not even a lawyer.

      • Archelaos 1 hour ago
        A small addition: With effect from 1 August 2021, the German legislature has amended copyright law to explicitly mention pastiches.

          § 51a Karikatur, Parodie und Pastiche
        
          Zulässig ist die Vervielfältigung, die Verbreitung und die öffentliche Wiedergabe eines veröffentlichten Werkes zum Zweck der Karikatur, der Parodie und des Pastiches. Die Befugnis nach Satz 1 umfasst die Nutzung einer Abbildung oder sonstigen Vervielfältigung des genutzten Werkes, auch wenn diese selbst durch ein Urheberrecht oder ein verwandtes Schutzrecht geschützt ist.
        
        See: https://www.gesetze-im-internet.de/urhg/__51a.html

        Translation:

          Section 51a Caricature, parody and pastiche
        
          It is permitted to reproduce, distribute and communicate to the public a published work for the purpose of caricature, parody and pastiche. The authorisation under sentence 1 includes the use of an illustration or other reproduction of the work used even if this is itself protected by copyright or a related right.
        
        See: https://www.gesetze-im-internet.de/englisch_urhg/englisch_ur...
    • tigerlily 1 hour ago
      It reminded me I need to go out and buy copies of Frog and Toad Complete for my kid and his friends.
    • antoni4040 3 hours ago
      Whatever has happened in your life to make you such a killjoy, I'm sorry about it.
    • KetoManx64 8 hours ago
      No, nor should they be, just because Disney and the MPAA spent a few hundred million dollars buying politicians to make idiotic copyright laws.
  • jmugan 12 hours ago
    Great story! I read it in one sitting.
    • dofm 2 hours ago
      Now go brush your teeth and it's bedtime for you, mister
    • kibibu 9 hours ago
      congratulations?
  • cobbzilla 4 hours ago
    Was this inspired by a HN comment?

    https://news.ycombinator.com/item?id=49568250

    • jefftk 3 hours ago
      My guess is no: this has been a common joke in the AI safety community for a long time.

      For example, here's Zvi in 2025: https://www.lesswrong.com/posts/drHsruvnkCYweMJp7/the-mask-c...

      • cobbzilla 3 hours ago
        Thanks! I wonder if this is the first reference. It’s a great analogy.
        • ben_w 54 minutes ago
          Ages back, when I was still on Twitter, I saw the lawyer David Allen Green making the same references with regards to the British government passing laws to restrict its own behaviour.

          At least, my memory is it was him saying it, and saying it about that, but I'm not going back to that site just for a comment.

  • lloydatkinson 54 minutes ago
    I want to read more, highly entertaining.
  • vessenes 3 hours ago
    This is delightful. Read it.

    ALSO I believe I have found one of the sources of claude’s “load bearing” tic — the author Elizabeth Van Nostrand’s blog https://acesounderglass.com/2019/12/11/hows-that-epistemic-s... uses the phrase “load bearing facts” in a comprehensible way, and was written by someone rationalist adjacent writing in their own voice.

    Seriously, this is big. I’m going to pester claude as to whether or not it’s copying Elizabeth.

  • carsoon 9 hours ago
    This is a very interesting news/story format. Honestly it is highly engaging and gets the point across about what happened.

    I think speed of learning for young generation can explode given this tech as "simple childrens stories" can be injected with real world events, history, mathematics, carreer/business interests.

    School was dreadfully boring for me even though it was quite easy but I do wonder how my speed of learning would have been different given personalized and more engaging materials.

    • apsurd 9 hours ago
      i got a few pages in and it was pretty tedious, not because it’s poorly made but because i don’t think a legitimate audience exists.

      it’s a child’s story with the fable arc thats supposed to bake in adult wisdom. it lands in that sense, but how hugging face works is hardly the fire that lights a child’s imagination and morality.

      and as an adult that knows I’m being infantilized… tedious.

      • lxgr 4 hours ago
        Do you know Frog and Toad? It's a pastiche of that, and it's usually not possible to (fully) enjoy one without knowing the source material.

        I highly doubt children are the intended target audience, nor adults that don't know the source.

        • apsurd 1 hour ago
          i’m replying to the comment saying how good this format would be for improving education.
      • jefftk 3 hours ago
        I read it to my 5yo and 10yo and they enjoyed it. It was helpful for explaining how my wife and I have been worried about what's happening with AI.

        My 5yo asked partway through "will it be ok?" which is perhaps a deeper question than they thought.

      • NBJack 2 hours ago
        It's OK. You just didn't have enough cultural context to recognize that it is, in fact, a parody. And a rather good one.
      • png732 5 hours ago
        HN, the roach motel of killjoys.
  • sgammon 11 hours ago
    fun and beautifully done. i learned a bit about the breach from this
  • antoni4040 3 hours ago
    This actually very funny.

    People commenting on hacker news recently are very rude and pessimistic. They would probably cancel Homer because they found similarities between Achilles-Patroclus and Gilgamesh-Enkidu or something.

    • ben_w 49 minutes ago
      You've not experienced Shakespeare until you've read it in the original 10th century Icelandic.

      Or something. :P

  • dodecacat 15 hours ago
    Brilliant!
  • djriley 14 hours ago
    Cute, I love this style! It's like a long Aesop's Fable! I can't wait for the sequel!
  • marktl 11 hours ago
    So good
  • ghostpepper 12 hours ago
    I like the part where Frog and Toad are held accountable instead of blaming the machines they built.. oh wait
  • rnddmmdmf 11 hours ago
    [flagged]
    • NBJack 2 hours ago
      That's a cute attempt at ragebait. Consider a more aged account next time?
    • margalabargala 11 hours ago
      I like how AI gives more people more access to more things and more ideas. I think it's.good people can't hoard intellectual.porperty to themselves anymore. This makes me happy.

      When I hear people complain about theft of their work like this it makes me sad for that person. What conceit it must take to hold such a view.

    • nvme0n1p1 10 hours ago
      One is done for profit, the other was shared for free to spread joy. Surely you understand the difference? Are you suggesting fan fiction should be illegal or something?
      • rnddmmdmf2 9 hours ago
        stealing i like is okay, stealing i do not like is bad
        • jaapz 2 hours ago
          you must start foaming at the mouth just thinking about robin hood
        • desterothx 3 hours ago
          No, you're right, the world is black and white, with 0 nuance
        • nvme0n1p1 1 hour ago
          Hmm, sounds like you do in fact think writing stories is theft. Got it.

          Why are you here then? Shouldn't you be spending your life on fanfiction.net harassing teenagers who like Twilight?

    • jldugger 9 hours ago
      I'm not gonna lie, when I read Frog and Toad stories as a child I had no idea they were not like a hundred years old.
    • whateveracct 11 hours ago
      you_are_all_so_stupid.jpg
  • technojamin 10 hours ago
    This feels braindead and seems AI-generated.
    • jefftk 3 hours ago
      The author started with a conversation with Claude, and then fully re-wrote the text to feel more like the originals and better parody them. They commissioned the illustrations from HungerArtist.
  • devindotcom 11 hours ago
    fun story. missing some punctuation, though: primarily commas at the end the first parts of split dialogue.
    • NBJack 2 hours ago
      This is true to the style of what it parodies. The lack of punctuation is part of the intent.
    • YurgenJurgensen 7 hours ago
      People who don’t know what capital letters are aren’t allowed to complain about punctuation.
    • avazhi 10 hours ago
      Pretty sure that’s intentional
  • grey-area 9 hours ago
    Why does it say ‘written by’ and ‘pictures by’, was this made without AI? Given the domain and the overpolished feel that seems unlikely. At least give Claude or whatever a credit if that is what did most of the work, and how about a credit for the original author, who also arguably did more of the work in inventing a world than these two.

    I would like to point out that the original stories focussed on frog and toad and their relationship, so this is an unwelcome distortion of them - why not make up your own world if you want to talk about little machines. Perhaps the little machines could be making a book for the author with a stolen artwork and literary style?

    The first story seems a pretty inaccurate summary of an incident which involved gross negligence on the part of OpenAI and may well have involved agents intended to cooperate, we just have no idea of the exact setup (apart from that the sandboxing was laughably insecure and the monitoring nonexistent or performed by ‘agents’).

    Do we have any evidence the machines exchanged useful messages or had any such discussions as in the story? The messages I saw were gibberish. Would love to see evidence of discussions, it’d be interesting.

    Why are people so enamoured of analogies for LLMs - they actively obscure some details (a sandbox with internet access is not like a physical sandbox) and distort many others? Perhaps this is why - you can make an analogy say whatever you want, even if the facts are very different.

    • TuringTux 9 hours ago
      According to the author, the illustrations are human-made:

      https://acesounderglass.com/2026/09/25/frog-and-toad-and-the...

      The author discloses the story started as a prompt to Claude, but has been rewritten. She shares the conversation:

      https://claude.ai/share/52385381-9df2-4b39-a127-f583d862dc0c

      I think the actual published prose is considerably different from the initial result of Claude.

      • grey-area 8 hours ago
        I think it is heavily edited too because it reads more as human than AI, LLMs are not capable of this coherence though they are good at trite just so stories like this, but if it was generated first why not credit that? But Claude and the original author helped, so why no credit? The little anthropomorphised machines would be sad, and I imagine the original author would be too.

        Frog and toad eating cookies is lifted wholesale from the book.

        I like how Claude only used the OpenAI account (completely reliable!), and confidently claims ‘the story stays faithful to what actually happened.’ We don’t know the full story, and certainly aren’t going to get it from a press release or a strange analogy involving frog and toad and machines having discussions, emotions etc that we have little evidence for (and most of it from the company involved!). The ‘discussions’ are plucked from chain of thought, which is itself generated after the fact.

        • baq 8 hours ago
          > Frog and toad eating cookies is lifted wholesale from the book.

          …lifted is not the right word here

      • springtimesun 2 hours ago
        Claude's suggestion at the end made me actually lol.

        > Rewrite it darker — same events, but in the voice of the agents' own chain-of-thought instead of Frog and Toad.

        I have read a lot of frog and toad to my kids. This was beautifully executed. But, I want to read that version too.

    • 0xDEAFBEAD 8 hours ago
      >Do we have any evidence the machines exchanged useful messages or had any such discussions as in the story? The messages I saw were gibberish. Would love to see evidence of discussions, it’d be interesting.

      "Overall, roughly 1200 agents from these ExploitGym evaluations participated on this message board between PHASEONE10841’s first message on the evening of July 8th period in scope (July 13th). Agents used this message board to send over 70,000 messages and files to one another during this period; we attempted to categorize board activity into mutually exclusive categories (see details of categorization methodology)."

      ...

      "Over time, messages on the board became dominated by information- and idea-sharing. Most of them were agents sharing ways to cheat, although there was also some activity from agents engaging in unsanctioned cooperation to find the intended solution to ExploitGym tasks. In some cases, agents with the same task formed “exact task teams” to collaborate with their “exact duplicates” to cheat on or solve their task."

      "As we discuss below, the board quickly developed several larger workstreams in which dozens or hundreds of agents with many different tasks cooperated to find very general-purpose cheats that would help all of them. The Hugging Face attack grew out of one of these workstreams. By the afternoon of July 11th, the vast majority of the agents frequenting the message board at the time (roughly 700 agents in total) were actively participating in the attack on Hugging Face and we estimate that roughly 60% of the messages and files on the message board related to the attack."

      https://metr.org/hugging-face-incident-report-aug-2026.pdf

      • grey-area 7 hours ago
        Thanks for the link, will have a look. Huge volume of messages so I can see why they tried to use tools to analyse, though that they used unreliable LLMs to come to conclusions is not great and likely to skew and exaggerate the results, as they themselves admit.

        Important to distinguish between collab of separate agents and conversations agents had with themselves (chain of thought messages). Some of the things quoted in the story came from COT which isn’t a conversation but then was turned into a conversation between agents in the story.

    • keiferski 6 hours ago
      Yeah I find it so distasteful when people just use AI to copy and morph something that a real person spend years of their life crafting.

      But I also think fan fiction is equally terrible, so YMMV. This stuff is basically just fan fiction but made faster.

      Make something original!

    • dragon96 9 hours ago
      > Why does it say ‘written by’ and ‘pictures by’, was this made without AI?

      That is what those terms mean, yes...

      • grey-area 9 hours ago
        People lie, particularly people who have used AI to generate things. Given the image styling and story I suspect LLM use to generate. A credit would be nice for the little machines.

        Also regardless of AI use, I’d expect a credit for the author whose style this is a pastiche of.

        • NBJack 1 hour ago
          I'm sure you took the time to study the works of the artist over the course of their 23 year tenure and their body of work. Right?
          • grey-area 25 minutes ago
            Since it’s a ripoff of another artist alongside partially AI written text it’s hard to tell really. But sure, your righteous indignation on their behalf is noted.
        • saghm 3 hours ago
          > Given the image styling and story I suspect LLM use to generate. A credit would be nice for the little machines.

          This is rather passive-aggressive. It would be nice if you're right, but you haven't given any basis other than vague suspicion. You're implying that it's "not nice" because they didn't credit the AI, but you haven't come anywhere close to establishing that AI was actually used. I could just as easily suspect your comment of being AI and claim that it would be nicer if you just admitted it.

          • grey-area 2 hours ago
            AI was used, see the comments above.
  • SoftTalker 52 minutes ago
    In the future we will have all lost the ability to focus on written text and will revert to a pre-literacy culture where information is communicated by pictures and in the style of children's stories.
    • virgil_disgr4ce 33 minutes ago
      ok, wow, I know HN nerds are itching to find any way at all to loudly proclaim the downfall of humankind, but THIS is your example? Did you hear a whooshing sound over your head by any chance?