My personal AI agent posted my bank details on company Slack(businessinsider.com) |
My personal AI agent posted my bank details on company Slack(businessinsider.com) |
This is not the kind of story I would want to publicize if I were a CEO.
Whatever data goes in, it will output it in some way. Humans gotta understand that.
"Agents" can be very "persistent" and when not sand boxed appropriately can get at things they were not meant to get at. Even if its only 1/1,000,000 that one time that one time is going to keep making the news
Explaining that to the general public when facebook is pushing Muse on everyone will be difficult so its going to get worse before it gets better (if it gets better)
Humans will continue to mistake these 'agents' for agents with agency and understanding because of the way they are sold and described.
AI products are not regulated like every other consumer product. If your bank’s app had a big green “share” button shadowing the “close dialog” which shared your personal info in the same manner, any sensible regulator would like a word with your bank’s IT department. If your teller handed you a paper with a small print saying “by signing you approve this transaction being shared with your boss” likewise regulators would put a stop to it.
"The things they'll be able to do for us are going to be awesome. People will want them, and they are really useful."
Feels like someone has AI stock they need to see go up.
Even without agents being involved that’s a recipe for trouble.
I think it perfectly illustrates that even though an agent can give you the abilities, it's still up to the driver to make decisions.
In this case the CEO could have consulted someone with your expertise. Same ability, but vastly different experience.
There are probably so many people like this out there. We cannot expect the public to simply not use these features.
According to the article he is the CEO of a XMTP Labs, a "web 3" company, so, I dunno.
"XMTP Labs — How do we build things we can trust?"
What else has the agent seen?
"XMTP is the world's new private line. Send messages and money securely between people or agents — with no company or country in the middle."
"Let me know any flaws in the project"
Where? Where exactly? What email? What chat app? what channel? what restrictions? When not to?
Letting AI assume they know will bite you hard in the ass. The same applies to coding apps with agents. If you don't set clear boundaries, scope, limits, versions, roadmaps, etc before you embark on any project, you'll be doing it after the results you get are not what you expected, there is no escape
Detailed planning or damage control, pick your poison
things were so much easier back then, weren't they?
i was there, 3000 years ago...
Surely no-one that dumb could operate a phone let alone be a "CEO"
So the first people who'd be overly trusting of things they don't understand would be exactly a CEO.
It’s quite useful since it correlates spend with invoices and double checks things and tells me about spend out of line with the family’s usual behavior.
It can probably do all of these things if it wanted to but that’s a matter of the outbox. For world-actions you should outbox things.
Bank details are supposed to be given out - that’s how you send/receive money.
https://africa.businessinsider.com/news/my-personal-ai-agent...
Remember that Noah built his ark before the flood. And SuperDuper Intelligence might be doing the same thing.
I've had that within the last few days.
I happened to be vaguely watching an agent at work on a longer task and spotted it attempt to find a way around not having access to a local service that would greatly help it achieve the task, I immediately chimed in with a "STOP! if you need access to X then just ask!".
I suppose my prompting could be improved :/
You can't stop an agent from leaking your information by telling it not to leak your information.
To prevent information from moving between your work domain and your personal domain, or between your communications-with-board domain and communications-with-journalists domain, then the agent for one domain must be physically and deterministically blocked from accessing information in other domains.
I mean it’s not wrong but I was like maybe not do that without asking first.
Why is it that somehow LLMs are given full clearance to dox, hack, spam, and scam without any liability?