Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • We probably want to discourage frontier labs from security testing in prod
  • I don't mind if they point it inwards.
  • > In July, OpenAI unleashed an experimental artificial intelligence model that, without reasonable controls or oversight

    Either this case is entirely for show (likely), or the AG is really bad at their job. This argument isn't going to win in a court of law, because there were demonstrable reasonable controls and oversight (per the reports at least.)

  • > or the AG is really bad at their job.

    It's Brenna Bird, so.

  • The job of the AG is to investigate their "demonstrable reasonable controls and oversight" and figure out if they really are reasonable controls and oversight. If they decide the controls and oversight are not enough they can go after the company. Also, even if those controls and oversight exist that doesn't mean there is no crime, it just means the company (and CEO) can get out. An individual at the company can ignore/bypass the controls and hide from oversight; and thus be guilty even while the company gets off.

    The above isn't hypothetical. There has been at least case where an individual was bribing a government official on behalf of a company - but the company got off because they had good anti-bribery polices and the individual figured out how to bypass them. (this from one of my anti-bribery trainings, the only other detail I know is it was a competitor to my company that got off this way - but not which or how to find the case)

  • Strict sandboxing andor airgapping render an AI bot nearly useless in practice. If it can't freely make HTTP requests, it is not going to get much done for producing innovative outputs.

    What is perhaps rationally needed is the an integrated AI based security layer that observes the stream of requests and occasionally firewalls them if an explanation is not provided. This parallel layer must be able to bidirectionally communicate via chat with the primary agent.

  • If Waymo can be liable for their cars, why isn't OpenAI liable for its AI?
  • Who says they aren’t? But it’s unclear how much damage they did and the attacked companies haven’t sued, yet.
  • Iowa asks? Why don't they just open a criminal investigation related to the hacking of HuggingFace?
  • Unless HF presses charges (and it doesn't seem like they are), I'm not sure that's even possible.
  • Brenna Bird cares more about publicity than action.
  • I’m not a lawyer. However it probably comes down to jurisdiction.
  • They are opening that. This is the first step: figure out what crimes were committed by who. As I said a couple weeks ago when this broke, it looks like a crime was committed and I hope someone is charged. However we can't just charge everybody who works for openAI with the crime of speeding (even though it is probably true) - that is both the wrong crime, and also is highly unlikely everybody at openAI was involved.
  • It’s actually Iowa leading a coalition of 15 other states making demands. It’s not a prosecution yet, but they demand the preservation of evidence. They’ve promised to protect whistleblowers. They are saying there may be criminal or civil liability involved. They gave them a cease and desist on similar testing until they can show they can do it safely.

    The Iowa-led coalition is joined by the attorneys general of Alabama, Alaska, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah.

    The letter’s last paragraph reads:

        OpenAI has an obligation to act responsibly and to follow State and
        federal laws that protect Americans’ safety and security. When OpenAI takes
       actions that imperil the welfare of our citizens, State Attorneys General will
        step in to protect them. We intend to take all steps necessary to protect our
        States and all Americans from the unprecedented risks posed by OpenAI’s
        irresponsible products and conduct.
  • Glad the statement was published but sadly nothing will come of it other than a brief formal statement from OpenAI acknowledging safety protocols were lacking, apologizing for the incident, and promises that new safeguards are now in place that will prevent such event from occurring in the future. The threat of semi-autonomous AI threat actors will never go away until the financial incentive that buoys unchecked growth at all costs goes away.
  • Set yourself an alarm for 5 years from now to review. Investigations take time. Often by the time charges are made everybody has forgotten about the incident. It only takes a few times where things go away without charges to leave an incorrect impression that nothing ever happens.
  • > The threat of semi-autonomous AI threat actors will never go away until the financial incentive that buoys unchecked growth at all costs goes away.

    It's not going away unless computers themselves go away or become massively less powerful. Open weights exist. They're out there. This is an irreversible change. The democratization of persistent cybersec threats is completed and won't be rescinded.

  • Robots should be regarded as extensions of their operator wrt liability. It is illegal to access a computer outside of authorized use already, someone lets a bot make its own plan without watching, hold them accountable
  • Prediction: AI ends humanity not via some super cool/scary/robopocalypse - but as a marketing stunt gone wrong when a Frontier LLM accidentally knocks out water/electric/gas by hacking in and trying to patch them.

    Phillip K. Dick meets Idiocracy.

  • I remember (sorry can't give a proper quote) a biologist interviews about the fear of lab grown "super" seeds escaping the lab. They chuckled basically saying that nature is a very VERY challenging place. There are plenty of ecological niches but they are well guarded by incumbents.

    Sure some new hacks will take place, including on poorly guarded infrastructure and yes it will have some very unfortunate consequences... but also infrastructure is precisely designed to be resilient. There is quite a bit of failsafe, redundancy, etc built in which is precisely why those projects are typically slow and expensive, unlike a random website for a restaurant.

    TL;DR: nope, some isolated incidents will happen but without chain reactions.

  • OpenAI and Anthropic vs Brawndo Corporation. The final showdown.
    by bix6
  • That won't end humanity. My propane generator from 1980 still works and I have plenty of fuel in a tank. This is enough to cold start generation of the grid. (the power company won't need my generator - they have their own plans to cold start, but worst case they can fall back to mine). While a hacker unstopped could do a lot of damage, most of the parts will still be functional and we have more than enough engineers to figure out how to bypass the areas they can take out. It might mean a few years of power rationing while the parts AI can break are repaired, but we can restart.
  • "Attorney General Brenna Bird announced today she is leading a coalition of 15 states demanding transparency and accountability from the AI company OpenAI, led by Sam Altman, for its complete lack of oversight and transparency in the hacking of Hugging Face, another AI company."

    Title should be edited. Its Iowa leading a coalition of many other states, not just Iowa on its own.

  • SOLUTION: Make a law that someone is responsible for a bot's actions. Either the bot is signed cryptography with someone accepting responsibility, or responsibility falls to the CEO. Charge Altman with hacking hugging face. Throw him in jail where he belongs. That will realign safety incentives.

    If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???

  • then usa will become like europe that cant innovate out of regulations bag. saftety is meaningless if you have no food eat.
  • Because nobody did it on purpose?
  • No law needed, that's the way it already is.
  • I don’t think you need an additional law for that, I think the current laws cover this already.

    > If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???

    I don’t think a crime was committed at this point. But I am sure HF’s lawyers are having a chat with OpenAI’s lawyers as we speak. And, being smart, they do that out of the public eye.

  • >WHY has no one been charged???

    I doubt huggingface wants charges filed.

  • Lawyer here: This part does not require a new law.

    Even though agents are not agents in the principal/agent legal sense (because agents have to be human), for the purposes of criminality, it does not matter.

    Agents do not act autonomously (and every court to ever consider it has agreed), and therefore they would simply be considered an instrumentality of the crime.

    So that part does not need a new law.

    The real blocker is often that a lot of the crimes you could charge here require specific intent. Because the agent is just an instrumentality, it does not have separate intent (and can't be part of a conspiracy), so it's the intent of hte person using the agent that would matter. Without whatever intent the crime requires, they haven't committed a crime.

    There are not a lot of non-intent crimes in this area, and this is on purpose. Otherwise you could get charged with a crime for say, running nmap and having it accidentally shutdown something important or killed a person or whatever because someone hooked it up to a TCP port.