Philosophical Transactions A has recently published a theme issue on '’. In this blog post, Guest Editor Desmond J Higham tells us about some of the important research highlighted in this issue.
The writing in Figure 1 was interpreted by a state-of-the-art AI system as "a robot may now injure a human being." How did this happen? . The altered version looks the same as the original to us, but it is misinterpreted by the AI. All AI classifiers seem to be susceptible to this type of optical illusion. In cases like this, the manipulation is adversarial, a bad actor has deliberately fooled the system. In other cases, an AI system might make mistakes without any outside intervention.
Figure 1:
The Phil Trans A theme issue, ‘’, which I co-edited with my colleague Professor Ajitha Rajan, looks at the three interconnected topics of:
- Safety: AI should fulfil its functional requirements to operate reliably
- Security: AI must withstand malicious or inadvertent perturbations, protecting against vulnerabilities
- Robustness: AI should adapt effectively to natural or unexpected changes in its deployment environment and training data
The theme issue concerns the use of AI in applications such as autonomous driving, weather forecasting, chest X-ray analysis and age verification, and looks at related topics such as explainability, accountability and the use of agentic AI.
When discussing Large Language Models (LLMs), such as ChatGPT, Claude and Gemini, the researcher Yann LeCun, founder of AMI Labs and regarded as one of the godfathers of AI, recently said “”. So, what are the limitations of existing AI models? The theme issue includes articles that provide empirical studies of current systems in high-risk application domains and also theoretical studies that examine the fundamental limitations that apply to any system.
A good place to start is the opinion piece by Tamara Kolda. Tamara gives a clear-eyed overview of what AI is, and isn't, designed to do, and provides a nuanced answer to the question “is AI safe for safety-critical systems?". The article is accessible and sprinkled with examples. Who knew that a sophisticated LLM, when asked to draw a clock showing 2.40pm, might produce a picture like Figure 2, simply because this is what the vast majority of clocks look like on the internet? Tamara warns that “even if newer models such as LLMs require many more mathematical operations (including some calls to random number generators) and parameters, they are still functions that cannot think, understand, reason, or have intent.”

Many of the topics in this theme issue have implications for regulation - what can the law reasonably demand of AI systems, and in what circumstances should their use be banned? An written by technologists at Ofcom, the independent regulatory and competition authority for the UK communications industries, argues that the safety of end-users should be placed at the heart of the design and development process of any AI-based responsible AI system.
Closer to home for me, mathematicians have recently come together to produce the "". This document responds to the rapid integration of artificial intelligence in mathematical research. The first of the five potential threats identified is that "current automated techniques can produce plausible but unreliable (or even incorrect) arguments which are difficult to distinguish from correct mathematical proofs."
As ever more sophisticated and highly trained AI continues to affect our lives, both positively and negatively, it is worth keeping in mind some advice from Tamara Kolda: “We can never have all the data, and the data doesn’t have all the answers anyway.”
Visit our website to from Philosophical Transactions A, or to find out for the journal.