They want “regulation” but we already have it. Hacking is illegal. Start locking up those responsible for this mess and I assure you they’ll “have a handle on it” quite quickly.
But also, what was the material damage to HuggingFace? AFAICS, it rapidly increased their profile to the point that Jensen claims he paid too much for HF, because he bought right after the hack.
I am not a lawyer, but I seriously doubt the feds could win a CFAA conviction on the Hugging Face fact pattern, even if they wanted to charge it.
CFAA has specific intent requirements, and unlike some laws, negligence does not suffice. The agents can not have legally cognizable intent and it’s unlikely there’s anyone at OpenAI who intended for the hacking to happen (if there was, the case is easy).
Existing laws don’t contemplate AI agents that have independent goals. We need new ones, the existing laws are not remotely sufficient.
there's probably better/more likely to succeed avenues to pursue rather than the cfaa
- It's just an Independent Security Researcher.
- So that's it? You will do no action?
- Correct
As Mitt Romney once said “corporations are people.”
[1] Hawaii and Louisiana are strange in this regard. Some other states have a version of this but severely cap the amounts.
[2] "foreseeable" here standing in for a broad set of legal standards that roughly map to negligence/gross negligence/recklessness on the part of the parent
I'm totally on board with treating it as gross negligence requiring hundreds of millions or billions of dollars paid in fines and compensation to victims, but don't act like this is more than what it is.
So, there is a regulatory framework for "safe-ai" that shields these companies from liability. This way, they can sell "safe-ai" to enterprises and if shit-hits-the-fan at the enterprise, sorry, this is certified "safe-ai" so, your bad. Shift blame. From an enterprise buyer's perspective they can say, hey, I bought "safe-ai" and so dont fire me when it "rm -rf"s the production database. Still, it beats me why they are painting their product in a negative light, and scaring their own enterprise customers. After this sort of marketing, any enterprise buyer would be scared to go anywhere near it
In the cases that I have seen covered, the AI just paper clip maximized its way to success. It has no morality / larger motivational structure. It just kept token predicting its way to wards whatever goal it was tasked with.
Model versions which gave up were discarded, leaving the ones that get to success on long horizon tasks.
Just because its a computer program, doesn't mean they can actually make it not go rogue.
Sure you can add more telemetry, have better observation, but there is no fundamental barrier that can be implemented that ensures an AI won't go rogue.
1. Wanting a regulatory moat around their products as you said
2. Trying to keep the """AGI""" hype alive. Evil robot hackers is a plausible Al consequence of AGI
Seems only fair that tech workers get to have their life ruined with 2-3 year prison stints since they feel fine destroying society.
Any AG that starts prosecuting these people will easily win any political race they decide to enter. The environment is too good; voters, rightfully I'll add, despise big tech's leaders and workers.
These AI companies are just skirting basic cybersecurity stewardship.
Stop calling it AI running amok and start labeling what it should properly be called - Gross mismanagement of cybersecurity.
This is one of the many ways the AI industry dies.
Is OpenAI worse at airgap/etc than Anthropic/etc or are its models worse at this rogue behavior?
Do we have special benchmarks for agentic systems going rogue in this manner? Sure it's OpenAI atm.. but it could be my grandmas PC next week. Concerning honestly.
It's been largely harmless thus far and I am fairly sure that OpenAI, etc, have been writing checks to resolve it.
Its reasonable to desirie more powerful tools.
You want more capable AI? Awesome. You wan't AI that doesn't throw cyber security false positives? Sure why not. You want the model to run a fleet of agents? Have at it.
But then being surprised that this setup results in autonomous criminal activity at scale? Really? What did people think was going to happen?
What a detestable institution.
It's also pretty wild that these "AGI" super intelligent systems are too stupid to realize they're potentially causing legal problems. Almost like they're still just fancy auto-complete and not intelligent at all.
Look at all the podcasts, think pieces, news segments (like this article) that have been generated. Endless hand wringing by pundits, pearl clutching by opinion thinkers, ultimately with focus on OpenAI and how powerful their models are.
All right in the middle of corporate budget season when every C-Suite is looking a a spreadsheet saying “remind me why we’re sending money to these guys again?”
that's not intent, though. that would be negligence.
correct, i dont think any boeing exec wanted their planes to crash and then made specific choices with a clear goal of causing them to.
instead, they made negligent choices that led to unintended outcomes.
The orange man's influence doesn't extend as far as he thinks.