Ant’s 韦韬 on Confidential Computing and Higher-Order Programs
Summary
The industrial dividing line in this AI cycle is not whether models can generate content, but who can put a “general-purpose intelligence engine” into reliable production. 韦韬 believes frontier models have surpassed many ordinary people, yet still delete files, fabricate references and get basic questions wrong; what is truly scarce is industry knowledge above the model, clear convictions and fact-checking. “Your understanding must be higher than the model’s, rather than being replaced by it.”
The core value of confidential computing is that data can still be processed, combined and verified without moving in plaintext, turning security from a brake into an accelerator. Data owners control permissions and result disclosure through keys, while operations and R&D staff cannot see intermediate plaintext; 韦韬’s analogy is that without brakes, no one would drive at 120 on a highway—yet the more complete the safeguards, the more willing institutions are to release high-value, highly sensitive data.
This infrastructure has moved beyond proof in papers and into quantifiable use cases including agricultural lending, new-energy vehicle insurance and commercial health insurance. Agricultural loans use a remote-sensing model to assess assets and confidential spatiotemporal computing to verify land, expanding from one Jiangxi county in 2023 to all 2,688 counties nationwide; new-energy auto insurers, facing loss ratios above 100%, combine vehicle, driving-behavior and insurance data to identify risk and improve pricing; a medical-insurance and commercial-insurance settlement center launched on June 26 and supports direct reimbursement. “Farmers have no idea what is happening behind the scenes; they simply enjoy the convenience.”
AI will expand demand for confidential computing because companies cannot ignore the productivity of frontier models, yet cannot send sensitive data directly to public internet services. Private deployment is expensive and slow to upgrade; 韦韬 says public clouds can materially lower inference costs through technologies such as P/D disaggregation, with “full-strength DeepSeek” on Alibaba Cloud priced per token the same as Qwen 3; even with confidential computing added, the public-cloud solution remains far cheaper than a private all-in-one machine.
韦韬 attributes the unreliability of large models to “workshop-style usage,” rather than waiting for hallucinations to disappear from the Transformer. His higher-order programs use natural language to carry knowledge and programming languages to carry boundaries and logic, then break tasks down through “making them explicit, controlled and contract-based,” verify them step by step and test them against scenario data. “We are using it wrong” means AI should be organized as an industrial production line, not asked to handle everything end to end.
Production-grade AI may not be ruled by the largest model: specialized 32B-class models may offer better cost and control than giant general-purpose models. 韦韬 calls Qwen 3’s 32B model “a production-line model,” emphasizing that it can run on a single card; 235B and 480B models are better suited to Copilot-style expert interaction, but are not necessarily more reliable than smaller models. “Different vehicles need different engines.”
AI is also democratizing cyberattack capabilities, leaving the security industry facing a widening gap between falling attack costs and rising defense complexity. Criminal operators who once paid hundreds of yuan to outsource tools can now use Cursor directly; 韦韬 even says that “more than 95%” of programs written in Easy Language, which lowers the barrier to Chinese-language programming, are tools for the gray and black markets. Attackers need only find one opening, while defenders must build a defense-in-depth system with no gaps.
The key to commercializing confidential computing is not selling expensive algorithm modules, but making the data businesses built on top generate dozens or even hundreds of times the infrastructure investment. Ant began R&D in 2016, open-sourced SecretFlow in 2022 and then moved into commercial services for small and midsize enterprises; open source expands the talent pool and adoption, while commercialization handles delivery, operations and broader access. “The truly valuable thing is not the privacy-computing module itself, but the data businesses running on top.”
Deep dive
1. Large Models Become General-Purpose Intelligence Engines for the First Time—but Still Have Human-Like Highs and Lows
韦韬 has lived through multiple waves of technological change, from the internet’s arrival in China in 1993 and 1994 to today. In his view, even AlphaGo was a specialized system; this is the first time humanity has built a “general-purpose intelligence engine.”
That generality brings both an exceptionally high ceiling and an exceptionally low floor: a model may outperform an ordinary college student at math or Olympiad problems, yet also make elementary mistakes or “delete files at the drop of a hat.” It is not an omniscient machine, but a general intelligence that can make mistakes.
The application that still impresses him most is AI-assisted programming. The entrepreneurial-era problem was “everything is ready except a CTO”; now someone who cannot code can describe a requirement and potentially get a complete, runnable App from a model.
His own signature utility began with a single request: convert PPTs whose formatting might break across systems and versions into images, then regenerate them as PPTs with the layout locked in. Small pain points that were not worth developing by hand can now be solved quickly.
2. AI Can Write for People, but Not Replace Experts’ Convictions or Accountability for Facts
韦韬 does not care whether a subordinate’s report was generated by AI. What matters is whether it contains a core view capable of influencing an industry and moving things forward. “Your understanding must be higher than the model’s” if you want to guide it toward the content you need.
Large models are good at eliminating writer’s block, but cannot take responsibility for an expert’s judgment. Professionals who once had strong views but struggled to write can now ask a model to express them from different angles; without a view of their own, smooth prose is still just a pile of words.
He explains hallucinations as “lossy compression”: broad patterns can be compressed, but historical facts are full of contingencies. At a high compression ratio, once a fact is compressed incorrectly, even perfectly valid rule-based reasoning afterward will produce a conclusion that is wrong at the root.
Korgi once used ChatGPT to search for the claim that “韦韬 writes site rules more seriously than love letters.” 韦韬 immediately judged it to be a hallucination, and said it was “most likely talking about 刘佳.” He also acknowledges the creative value of imagination, citing Mendeleev’s dream of the periodic table and Kekulé’s dream of the benzene ring, but says factual applications must be checked item by item.
3. MIT BBS Showed 韦韬 That Community Evolution Matters More Than Rules Alone
MIT BBS began after 刘佳 received an offer from MIT. 韦韬, then working at Founder, participated in its early technical build-out and later stayed mainly in China, continuing to provide support when technical problems arose. It gradually brought together students from Peking University, Tsinghua University and elsewhere who had gone abroad, becoming the “spiritual home” of a generation of North American Chinese students.
The early builders once devoted enormous effort to drafting site rules, only to discover that “rules alone cannot solve many of the problems.” 韦韬 compares community governance to the balance between rule of law and rule by morality: rules cover only part of the terrain; a healthy ecosystem, shared sentiment and self-discipline determine whether a community can continue to evolve.
4. AI Is Democratizing Attack Capabilities, While Defense Must Still Cover Every Gap
韦韬’s security judgment is blunt: “Technology is generally simpler to use for attacking.” Attackers need only find one entry point, while defenders must create a seamless, defense-in-depth barrier across every dimension.
Criminal operators are adopting new technology much faster. Ant once encountered people who could not program but paid community programmers a few hundred yuan to write attack tools; with AI coding tools such as Cursor, that outsourcing barrier may disappear entirely.
His stark example is Easy Language. It lowers the programming barrier through Chinese, yet, in his observation, “more than 95%” of its programs are tools for the gray and black markets. The criminal ecosystem includes elite groups capable of “moving heaven and earth” internationally, with research institutes and banking resources, as well as a vast grassroots layer causing widespread damage with simple tools.
5. More Than Two Decades of Attack-and-Defense Experience Show That Security Victories Usually Happen Where No One Can See Them
韦韬 entered frontline work by planning Beijing’s Olympic bid website in 1999, then building it and taking responsibility for security in 2000. When Beijing won the bid in 2001 and people were banging gongs in the streets, he stayed upstairs guarding the site. His team’s defense system has delivered “basically zero incidents” over the years.
In one dark-web case involving the sale of personal information, multiple companies spent months tracking the operation. The Ant team narrowed a suspect list of more than 100 people to the target and helped police make the arrest. The case later became what he called the Ministry of Public Security’s “No. 1 personal-information protection case.”
Such results do not mean the pressure has eased. Anonymous networks, rapidly evolving attack tools and industrial chains at different levels are intensifying the contest; the security infrastructure, regulators and experts’ understanding are simply improving in parallel.
6. The Cheapest Way to Protect Personal Privacy Is to Disrupt ID Mapping at the Outset
韦韬’s first piece of advice to ordinary people is not to manage hundreds of passwords, but to “not use your real name” when sending packages or filling in logistics information. What black-market operators and internet services most want to complete is ID mapping—linking data from different sources to the same individual.
A pseudonym can materially increase the difficulty of matching records across databases. Phone numbers can also be isolated through dedicated numbers, while recycled numbers have already made many identity-mapping systems messy. The point is not to ensure that no single data point ever leaks, but to prevent all information from being easily stitched into a complete profile.
He supports the direction of a “digital identity certificate”: services requiring real-name acceptance would hold the true identity, while ordinary internet services would receive only a pseudonymized credential. If ID mapping can be disrupted institutionally and technically, the cost of protection will be far lower than trying to stop data trading after the fact.
7. The Main Risk of Facial Recognition Is Abuse; Identification and Liveness Verification Are Not the Same Thing
韦韬 opposes rejecting facial recognition wholesale over privacy concerns. He calls the face “the best technology, without exception” for connecting online and offline worlds: QR codes and NFC require a powered, connected device that has not been lost, while the face can serve as the final check when other methods fail.
Facial recognition answers “who are you?” Facial identity verification must also prove that “the you appearing now is alive and real.” Many companies that excel at AI recognition have not crossed the technical gap into secure verification; the two capabilities cannot be treated as interchangeable.
The truly difficult problem is collecting and using faces without consent. 韦韬 believes trusted technology can confine facial data to agreed-upon scenarios, balancing authentication capability with abuse prevention; simply banning it would amount to “throwing out the baby with the bathwater.”
On generated video, he says that “fooling the human eye is not particularly difficult,” while fooling professional computer analysis remains far harder. In films, a car falling off a cliff can be sped up without hurting the viewing experience; similarly, an AI video may look lifelike while still leaving abundant machine-detectable flaws in fingers, physics and other details.
8. Confidential Computing Keeps Data Permissions in the Key, Not with the Operations Team
韦韬 divides industrial computing into general-purpose computing, intelligent computing and confidential computing: CPUs handle general computation, GPUs handle intelligent computation, while confidential computing addresses the outdated assumption that one must first obtain plaintext to use data.
In a confidential-computing pipeline, the computation, models and intermediate results from large-scale data processing all remain confidential. Execution is possible only in scenarios authorized by the data source, and only results agreed upon by both sides can be disclosed in plaintext under key authorization.
No one—whether involved in system development or operations—can directly obtain the relevant plaintext. This protects data that is easy to copy, alter and abuse, while allowing its value to be realized in lending, insurance, healthcare and other businesses.
韦韬 turns around the common image of security as a brake: “If there were no brakes, would you dare drive at 120?” Most of the safety systems covering roads, vehicles and rules are invisible, yet they are precisely what makes high-speed driving possible. Confidential computing is meant to play the same infrastructural role on the information superhighway.
9. Privacy-Computing Routes Differ Widely, but Attack Cost Can Ultimately Provide a Common Measure
Privacy-preserving computing is not a single technology. Multi-party secure computation and fully homomorphic encryption rely on pure cryptography; confidential computing relies on CPU memory encryption and a trusted system root; federated learning accepts some information leakage in exchange for greater efficiency.
Fully homomorphic encryption may offer the highest security level, but 韦韬 puts the cost at roughly 100,000 times slower than plaintext computation and about 10,000 times greater data volume: 1G of data could become 10T. Confidential computing keeps data encrypted in memory, decrypting it only inside the CPU Cache for computation—a form of “hardware confidential computing.”
Internationally, the prevailing view for years was that different routes could not be measured by the same yardstick. Ant has proposed a unified scale over the past two years that ignores implementation and asks instead how much cost and uncertainty an attacker must overcome to break the protection.
The approach is being used with the China National Information Security Evaluation and Certification Center to build standards and run pilots. 韦韬 believes it can apply not only to privacy-preserving computing, but also to broader data-security and cybersecurity evaluations.
10. Ant Confidential Computing Moves from Internal R&D to Open Source, Then Fills the Service Gap for Small and Midsize Enterprises
Ant began developing multiple privacy-computing routes simultaneously in 2016, gradually applying them to internal and industry use cases such as lending and risk control. The technology was validated in real businesses rather than remaining confined to papers or top conferences.
On July 4, 2022, the team open-sourced the technology in Beijing under the name SecretFlow, witnessed by academician 王海云. The open-source project quickly attracted companies in China and overseas, but most users already had strong technical capabilities.
Small and midsize enterprises cannot easily deploy and operate complex security infrastructure from code alone. The team therefore established the commercial company Ant Confidential Computing to make the technology “truly accessible” through products and services. Open source and commercialization serve different users rather than simply replacing one another.
The National Data Bureau’s push to allocate data as a market-based factor has created policy support and industrial demand. 韦韬 summarizes the industry’s old bottleneck as data lacking processing, integration and value verification; confidential computing addresses the prior obstacle that institutions do not dare to use data.
11. Agricultural Lending Turns Confidential Computing from an Abstract Security Technology into a Nationwide Basic Service
Farmers’ main assets are land and crops, but loan amounts are limited, and the interest income is insufficient to cover the cost of sending bank staff to inspect fields one by one. The commercial cycle therefore does not work. The problem is not a lack of demand for loans, but the cost of traditional verification.
Ant Group and MYbank use a remote-sensing model to assess land and crops, then use confidential spatiotemporal computing to verify the farmer-provided land against government data and confirm ownership. Both assessment and verification are necessary, and sensitive data never needs to be handed to the other party.
The project began in mid-2023 with a pilot in one Jiangxi county. After the results were validated, it expanded to several provinces and dozens of counties, then rapidly covered all 2,688 counties nationwide with support from the Data Development Center of the Ministry of Agriculture and Rural Affairs.
What 韦韬 values most is the service’s invisibility: “Farmers have no idea what is happening behind the scenes; everyone can simply enjoy the convenience afterward.” Technological trust replaces expensive physical travel and no longer depends on any single participant.
12. The Problem with New-Energy Vehicle Insurance Is Not a Lack of Data, but That Sensitive Data Owners Dare Not Connect
Electric-vehicle users may see monthly fuel costs fall from more than 1,000 yuan to just over 100 yuan in electricity, while premiums rise. 韦韬 says loss ratios for some insurers’ new-energy vehicle books exceed 100%—“every policy means one more loss”—creating a strong incentive to reform.
Risk does not come only from the battery. Integrated bodies, sensors and circuits are expensive to repair after a collision; EVs deliver strong initial acceleration, and a poor driving habit can mean “one press of the accelerator and a crash,” making human behavior a major variable.
Insurers need to combine vehicle data, driving behavior and insurance data to distinguish high-risk drivers from those with good habits, but all three datasets are highly sensitive. After Ant, insurers and automakers connected them through confidential computing, 韦韬 says the relevant premiums fell substantially.
13. Medical and Commercial Insurance, Along with Cross-Border Business in Africa, Shows That Data-Compliance Demand Is Not a Niche-Market Phenomenon
Medical insurance holds enormous volumes of high-value, highly sensitive data, while commercial insurers urgently need to connect to it. The data, however, is held separately by medical-insurance authorities and individual insurers. As recently as “last December,” experts were still writing that connecting the systems was merely “industry self-congratulation.”
On June 26, the National Healthcare Security Administration launched a medical-insurance and commercial-insurance settlement center. Ant Confidential Computing provided technical support, enabling full validation between the two sides without leakage or abuse, while supporting direct medical-insurance reimbursement and credit assessment.
Transsion also brought African use cases to a SecretFlow community event. 韦韬 sees digitalization accelerating across Africa as well, with cross-border compliance requirements already affecting risk control, marketing and data processing between countries. Privacy-preserving computing is not limited to China or Europe.
14. Public Cloud Plus Confidential Computing May Be Cheaper Than Building a Frontier Model In-House
Companies with data-security and compliance requirements generally prohibit employees from sending sensitive data to public internet models. But abandoning frontier models creates a productivity disadvantage, leaving private deployment as the alternative—with high costs, heavy operations and slow upgrades.
韦韬 believes public clouds are large enough to dilute inference costs through technologies such as P/D disaggregation. He cites the example of “full-strength DeepSeek” on Alibaba Cloud costing the same per token as Qwen 3; many companies have not realized that economies of scale are already reflected in API prices.
Adding confidential computing on top of the public cloud still leaves total costs, in his assessment, well below private deployment on an all-in-one machine. Companies can also continue receiving model upgrades without bearing rapid equipment depreciation or running their own operations.
This creates a direct opportunity for confidential intelligent computing: model providers gain scale efficiencies, while enterprises gain data isolation and permission controls. Neither side has to exchange sensitive plaintext as the price of cooperation.
15. The Obstacle to Putting Large Models into Production Is Not Hallucinations Themselves, but Workshop-Style Usage
Ant unveiled its higher-order program at WAIC “last month.” 韦韬 repeatedly stresses that the industry has misdiagnosed the problem as hallucination: “This is not a hallucination problem.” The real issue is that one large model is still asked to handle the entire task from beginning to end, with the expectation that it will never make a mistake.
Humanity solved reliability through thousands of years of engineering, yet with AI it favors natural language and rejects programming languages. Natural language is suited to carrying concepts and knowledge, but it is semantically ambiguous and lacks logical boundaries and priorities; it is not a complete carrier for reliable engineering.
He uses a classic joke to illustrate ambiguity: a wife tells her husband to “buy 3 jin of peaches, and if you see watermelons, buy 1.” He eventually returns with 1 peach. The Three Laws of Robotics can create the same problem, with “do not harm humans” potentially being reasoned into locking people indoors forever to protect them from outside dangers.
Higher-order programs are not meant to eliminate natural language. They let natural language carry knowledge and programming languages carry deterministic logic, then break complex tasks into small, industrial-line steps that reduce the model’s one-shot reasoning burden.
16. Making Tasks Explicit, Controlled and Contract-Based Creates the Reliability Loop for Higher-Order Programs
Making tasks explicit requires the model to express its processing steps, after which industry experts confirm whether they follow professional procedures. It also forces experts to convert tacit experience into knowledge that can be discussed and reused. Inputs can remain in natural language; the key is that the process is no longer hidden.
Making tasks controlled means breaking them down and adding deterministic and nondeterministic checks at the smallest granularity. Asking people to repeatedly check whether something “violates human nature” is exhausting, while asking a model to perform the check requires only task allocation and compute. The results expose the model’s capability boundaries instead of forcing out an answer that merely looks complete.
韦韬 uses multi-digit multiplication to illustrate the boundary: a model may go wrong as early as 8×8. In the past, ChatGPT would “come up with some answer no matter what”; after verification is added, the system clearly exposes exactly how far it can go.
Making tasks contract-based then tests them against real-world scenario data. If the results do not meet the standard, the program is broken down further and verification strengthened until it does. Reliability therefore comes from repeatable engineering iteration, not from assuming the next generation of models will naturally be perfect.
17. AI Must Escape Dependence on Humans as a Permanent Crutch, Not Human Control
韦韬’s work on higher-order programs continues his more than two decades of making complex systems safer and more reliable. Beyond security, the data-factor industry has another major gap: data-processing capability. Large models offer a chance to fill it.
He proposes a counterintuitive direction: “How do we get AI to cast off humanity as a crutch?” Models already outperform many ordinary people on the gaokao and Olympiad math, yet cannot independently complete basic workflows. The problem may lie not in the capability ceiling, but in how the work is organized.
Factories do not ask one person to complete every process, yet a large model is still asked to handle everything end to end. Production-grade AI should separate tasks, checks and accountability. Experts still define workflows and acceptance criteria, but no longer need to watch every execution continuously.
18. 32B Models Resemble Production Equipment; Giant Models Are Better Suited to Expert Copilots
韦韬 notes that although Qwen 3 also offers larger variants such as 235B and 480B, one of its core products is 32B. He calls 32B “a production-line model”: it can run on a single card, costs less and matches the fine-grained tasks of higher-order programs well.
Giant models are valuable as Copilots interacting with experts, but may be too expensive for high-frequency production lines, and their reliability may not exceed that of a 32B technical model. Scale is not the only variable in production suitability.
His analogy remains the engine: tanks and passenger cars do not share the same engine. Future models should be matched to task complexity, cost and reliability requirements rather than optimized around the pursuit of one model that can do everything.
19. Confidential Computing Commercialization Is Still About Establishing Benchmarks—First Letting the Industry Taste That “Crabs Really Are Delicious”
韦韬 compares today’s confidential computing to the cloud-computing push led by 王坚 more than a decade ago. The difference is that 王坚 was once called a fraud, while he says “at least no one has called me a fraud.” The advantage is a blue ocean; the challenge is also a blue ocean, requiring concepts, architecture, products and policy to advance together.
Ant itself is often the first to “eat the crab.” After agricultural lending was validated, it expanded rapidly; new-energy vehicle insurance grew from trials with 2 insurers to more than 10, with essentially every insurer now participating. Once technological trust is established, replication can accelerate.
Confidential computing provides a new form of infrastructure. The data processing, applications, integration and verification built on it without plaintext transfer are called “new circulation.” The security domain is no longer defined by exclusive assets and operational boundaries, but by key-controlled virtual domains that can scale, integrate and be audited.
Ant Confidential Computing can sell the full infrastructure or use leasing and revenue-sharing models. 韦韬 says the value of the businesses above often reaches dozens or even hundreds of times the investment in confidential infrastructure. The goal is not to raise the unit price of the technology, but to make data sources truly willing to inject data and business users truly able to achieve material results.
20. Data-Security Insurance Could Turn “Nothing Must Ever Go Wrong” into a Risk That Can Be Priced
Partners worry that a data breach could cause catastrophic losses, so 韦韬 is willing to promote data-security insurance. He describes California’s mechanism as “compliance-based entry with insurance as the backstop”: internet services involving personal information buy mandatory insurance similar to compulsory auto liability coverage, with insurers paying claims after a breach and raising renewal premiums.
China still relies primarily on administrative accountability and has not yet formed a closed loop with insurance, pricing and other market mechanisms. Participants therefore tend to demand that “nothing must ever go wrong.” 韦韬 believes the industry will be better able to develop sustainably once risk can be measured and insured through the market.
The technical foundation of Ant Confidential Computing is classified as Level 4 under China’s information-security protection scheme, which 韦韬 calls the highest security level available for commercial use. The team is also depositing its code with an authoritative national evaluation institution for security analysis, filing and traceable management.
His cost assessment is that deploying confidential computing from the bottom of the architecture is generally cheaper than adding multiple security products later, while providing stronger end-to-end protection. It is “the highest-security solution with the best cost-performance,” and a prerequisite for easing data participants’ concerns.
21. SecretFlow Was Open-Sourced to Make Security Transparent and Expand the Boundaries of Talent and Adoption
韦韬 once wrote about Ant’s open-source effort: “Open source is the first time in the history of human civilization that the details of an end-to-end engineering implementation have been shared with the world.” Books, patents and classrooms had never shown production engineering so completely; “we answered that expectation and did not betray that goodwill.”
His personal open-source journey began with Linux. When domestic CD burners first appeared in 1996, he burned and sold several hundred double-sided Linux discs, with Red Hat on one side and Slackware on the other. He later spent years studying the Linux kernel, GCC and LLVM, using open-source technology in network security and network-processor work.
Privacy computing especially needs open source because black-box security can create a “lemon market”: vendors turn parameters up to maximum strength when testing security, then down to minimum when testing performance, leaving outsiders unable to tell the difference. Transparent code makes security claims verifiable and gives university faculty and students a platform to develop.
Three years later, teachers and students were independently using SecretFlow to publish papers at top conferences, users were volunteering that “the code quality is excellent,” and unexpected use cases from Transsion and competing companies had entered the ecosystem. The community’s next stage is to move from a privacy-computing framework toward a full data-trustworthy-circulation infrastructure.
22. Open Source and Commercialization Are Not Moral Opposites; Broad Access Often Requires Both in Sequence
Korgi mentioned the joke that OpenAI should be called “Close AI” and Meta’s wavering open-source strategy. 韦韬’s response is that company-led open source will inevitably be tied to commercial strategy; no company can be permanently placed on a moral pedestal.
When a company open-sources at one stage, it gives up some commercial interest to advance the industry. When it closes the source at the next stage, it is making a new choice between commercial returns and ecosystem opportunities. Individual companies may change, but the open-source ecosystem accumulated by practitioners worldwide can still create balance.
SecretFlow also faced debate over short-term revenue. A module that might once have sold for several million yuan might no longer command the same price after being open-sourced, but it can bring in more customers. 韦韬 believes the truly valuable asset is the data business, not an individual technology module.
Open source directly benefits programmers, often primarily those at large companies. Small and midsize enterprises without deployment capabilities still need commercial delivery. If commercialization lowers the barrier to use, it is also creating social value and should not be set against “giving back to the world.”
23. In the AI Era, the Career and Education Moat Remains Systems Thinking, Tight Logic and Real Contributions
韦韬 once worried about educating his child, then shifted toward the view that people “must embrace large models.” The essentials remain truth-seeking, fact-checking, systematic learning and forming independent views. Large models hallucinate, information problems on self-media may become even worse, and both can trigger intense emotions; without sufficient understanding, people will simply be led around by the tools.
His fifth-grade child already uses Doubao and the Youdao translation pen, and has supposedly “passed Level 27 in Python,” as dictated. 韦韬 still advocates learning math, programming and robotics: programming is one of the few forms of logic training that can operate at scale, remain airtight and cannot tolerate arbitrary mistakes. Short videos are difficult to block completely, so parents can only control time and keep guiding.
A robot vacuum showed him a more complete form of industrial upgrading beyond AI: problems such as rollers getting clogged with hair and dirty mop water smelling bad have now been solved. He also recalls his father working on warhead systems for air-to-air missiles, and mentions the difficulty of developing PL-2 and supporting missile research through military-to-civilian transfer. The progress from household appliances to “the nation’s most important weapons” has come from decades of accumulated industrial capabilities.
Korgi cited data showing a 6% unemployment rate for U.S. computer-science graduates versus 3% for arts graduates, then asked how junior engineers can grow. 韦韬 acknowledges that senior programmers can multiply their productivity with AI and reduce the need for junior labor, but the answer is not to move away from computers. Open source has exposed end-to-end engineering, while AI can explain code line by line; those willing to immerse themselves and contribute to the community are facing “the best learning opportunity in history.”