The Diff is a newsletter exploring the technologies, companies, and trends that are making the future high-variance. Posts range from in-depth company profiles, applied financial theory, strategy breakdowns and macroeconomics.
## Adversarial Inference and Emily Post
One of the paradoxes of strict social rules—how to greet people, how to dress, which fork to use, etc.—is that the people most resistant to them are the ones who are actually liberated by them. If you want to be judged on your personal qualities, it seems egregious that someone might fixate on the fact that you wore a black belt with brown shoes. But one of the functions of these rules is to reduce the amount of information you get from how someone presents themselves. The Great Male Renunciation was a collective agreement not to compete sartorially, and to do so in other ways. Fashion, at least for most men who might have cared about it, switched from being graded on a curve to a simple pass/fail system. Other behavioral norms, like calling people "Mr. Lastname" by default until you're told otherwise, serve the same function: there are rules to memorize, but there's a finite number of them, and they're often written down somewhere, often accompanied some explanation of why they make sense.
Brains have limited bandwidth, so your assessment of superficial outward symbols, going from "where does this person fit into the hierarchy" to "does this person fit in?" means more bandwidth for other things.
Yesterday's issue briefly alluded to the idea that inference creates demand for inference because we'll use generative AI to filter the outputs of generative AI, and this maps nicely to the fashion question: if a growing share of inference demand is induced by inference, especially hostile inference, it means that many billions of dollars in capex are spent building systems that trick each other and systems that try to spot the trick. This will show up in many contexts:
- You might see partially autonomous hacking systems that show a bit more creative flair when chaining vulnerabilities together, but they could get caught by autonomous security agents that are constantly checking logs for new kinds of weirdness—in the future, a consumer device that you put in your pocket will have the savant-like ability to notice that SSH connections are weirdly slow.
- When you get a cold email that mentions where you went to school, before it hits your eyes, your inbox is going to check the sender's LinkedIn and see if they went to, or have any connection to, that school; it might also look for evidence of mass-outreach, like lots of kind of random connections. Meanwhile, whoever builds this system will be spotting patterns like this and re-prioritizing emails accordingly.
- High-touch scams often add a touch of realism by throwing in personal information, especially of the kind that people might assume isn't public. But when you get a text message informing you that there's a warrant out for your arrest unless you pay a fine right away, your agent may be able to flag for you that this could be fake.
- One fun one: long ago, The Diff noted that when people take control of high-profile Twitter accounts, they don't know how to exploit them for maximum profit. Now, if you compromise an account, it's easier to use an LLM to generate something they might plausibly say that's also profitable to a cybercriminal. (This fits some of the details of Airbnb CEO Brian Chesky's claim that a pretty clearly LLM-written thread about tokenizing real estate, was posted on his Twitter account by a hacker, though if these screenshots of the thread are comprehensive, the hacker apparently forgot the part where they says they’re launching a presale and that you can be part of it if you send your ethereum to a particular address.) But perhaps the next time this happens, you'll have some in-browser agent looking over your shoulder and identifying scammy tells, or just hiding the tweets entirely because they're slop.
And this is just what we've thought of so far. We're still at the point where most AI use cases fit into existing ones. That's even reflected in the interfaces; a question you might have asked via Slack a few years ago is still getting asked in a chat window, and typing text into a terminal is still the default way to tell a computer what to do. It'll be an odd general-purpose technology if its use cases are 100% substitution and not mostly new use cases. Some of those will be adversarial.
In this context, some token budgets are like defense budgets. There are multiple equilibria for how countries might spend their tax revenue on defense compared to other options. Which equilibrium you get is determined by who's the most hostile and militaristic; they're the ones who make "defense" more euphemistic. But that militarism correlates with other things that make those countries poorer overall, so rich countries can beat them. The US did this more or less deliberately to the USSR at various points during the Cold War. As the economic gap between the US and Russia expanded, it got more and more punitive for Russia to aim for having the biggest military. This also happened in the pre-First World War arms race to build bigger and better dreadnoughts. A dreadnought consumed more of Germany's steel supply than the UK's, so the UK could both outbuild and outgrow them. The same equilibrium prevails here: cooperative, positive-sum behavior creates more wealth than extractive, negative-sum behavior, because it enables more complex supply chains and a lower cost of capital. But those friendly, cooperative systems are always vulnerable to exploitation, and there's some equilibrium where they spend on mitigation but still tolerate some losses. It's an equilibrium that includes lots of visible waste and redundancy, but that's true in other places. You don't need to spend on spam detection if you don't have spammers, but having a spam filter is a choice that's more under your control than whether or not someone spams you.
But if there's an equivalent to proper etiquette, some very clean signal that a message is trustworthy, then the equation is completely different. You can ignore spam, and save a lot of inference. In this model, humans get more valuable as complements to AI because we're so limited; you can't spin up 100 parallel instances of someone, so if they're paying attention to you in particular, it's a big deal. AI is going after some parts of the service sector, but it's creating a new kind of service sector job as someone who says that this particular AI output is worth paying attention to.
## Elsewhere
### They're Gone!
Three years ago, The Diff wrote about a peculiar phenomenon: even though a company's price per share is arbitrary, and it's common for them to do pre-IPO splits or reverse-splits to get a normal one, companies that go public below $10/share tend to have worse returns, and the lower the share price, the worse they get. These IPOs tend to be for companies that ranged from real-but-tiny to businesses with funny prospectuses, usually in the that's-weird sense but sometimes sometimes funny in the ha-ha sense instead. Things like displaying their balance sheet as an image of a physical piece of paper, or going from low six figures in revenue one year to close to nine figures of revenue with 30bps gross margins. I had noticed over the last few months that I was adding fewer names to that watchlist, and that I was covering 10bps short positions faster than I was adding 20bps short positions in new scam IPOs. And it turns out that that effect is real, with only 13 microcap IPOs on major exchanges through the first half of the year compared to 80 last year.
There are still a few here and there. This one fits the template, and recently filed an updated S-1 to add Dominari Securities to their list of underwriters. Sometimes, what you can do depends on who you know.
### Insiders
Usually, the higher up you move in some organization, the more you have access to proprietary information that you could use to make advantageous trades. But one counterexample to that is that there are some jobs that aren't incredibly prestigious, but do involve handling detailed documents with timely and well-vetted market-moving information. In the 1970s, an employee at a financial printer traded on information from takeover announcements he printed. And now, Donald Trump's teleprompter operator has been accused of making over $100k from prediction market bets about speeches. One thing prediction markets do is to change the incentive for secrecy within organizations. There some some jobs that are high-trust wildly out of proportion to how well-paid they are, from administrative assistants with full access to their boss' email to cleaning staff who can see whatever's on someone's desk. It's always been theoretically possible to use that information, and perhaps sometimes it happens (the NYT once wrote a heartwarming article about a frugal secretary who had over $8 million when she died; she worked at Cleary Gottlieb Steen & Hamilton from 1947 through 2014, a period during which many mergers happened, that firm was involved in quite a few of them, and the SEC's investigative vigor varied considerably. She was probably just cheap, but might otherwise be considered a kind of Stochastic Robin Hood who robbed from the rich and donated the proceeds to charity after her death).
### Post-Browser
Google is tying some outside apps more closely into AI mode. Searching for something is part of the process of doing something, and if that something can be done through one of the existing platforms—watch this, order some of that, plan a trip to there, etc.—then it makes sense for Google to directly connect users to a company that can do that for them.
Disclosure: long GOOGL.
### Supply Chains
TSMC is increasing its US capex by $100 billion, to $265 billion, as part of a broader agreement to lower tariffs. The economic logic of free trade is rock-solid, at least assuming that there's no chance of losing access to key nodes of the supply chain. But if there is a chance that they will lose access to some critical input, the deadweight loss of tariffs is economically similar to an insurance premium. Insurance can still be a bad deal, but it is at least a deal with upsides and downsides. And in this case, one of Taiwan's considerations is that the US is an enormous source of demand that they wouldn't be able to replicate domestically, so in the event that they're forced to choose between tariffs and foreign direct investment in the US, they're really choosing between two flavors of the same downside.
Disclosure: long TSM.
### Complete Markets
Kalshi is introducing prediction markets for pharmaceutical approval. One feature of this market is that it's hedgeable: if you think the contract is mispriced, and the company in question is public, you can capture that mispricing without taking a direct gamble on the drug. Which means that these are really conditional-probability markets, which deconstruct the value of a biotech stock into the probabilities of different outcomes along the way to approval and sale. That's actually quite useful. It's also going to be a honeypot for insider trading, since it's pretty clear that people don't use the same norms in prediction markets as they do in equity markets (on the other hand, it will be harder to detect, since more people will have knowledge about a single company than about a wide range of them). Still, this is a case where prediction markets are net useful; if nothing else, there will be pressure from the equity market side if equities traders are losing money because the informed traders bet against them in prediction markets rather than equities.