5 ms·
Iowa-led states ask OpenAI to keep their bots on a leash
- sam_lowry_ 2mo agoIowa asks? Why don't they just open a criminal investigation related to the hacking of HuggingFace?
- iAMkenough 2mo agoBrenna Bird cares more about publicity than action.
- nozzlegear 2mo agoYeah, irrespective of her politics (which make up a disproportionate amount of her cases), Bird spends more time chasing the most polarizing issues she can find than actually helping Iowans.
- cautiouscat 2mo agoI’m not a lawyer. However it probably comes down to jurisdiction.
- cestith 2mo agoIt’s actually Iowa leading a coalition of 15 other states making demands. It’s not a prosecution yet, but they demand the preservation of evidence. They’ve promised to protect whistleblowers. They are saying there may be criminal or civil liability involved. They gave them a cease and desist on similar testing until they can show they can do it safely. The Iowa-led coalition is joined by the attorneys general of Alabama, Alaska, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah. The letter’s last paragraph reads: OpenAI has an obligation to act responsibly and to follow State and federal laws that protect Americans’ safety and security. When OpenAI takes actions that imperil the welfare of our citizens, State Attorneys General will step in to protect them. We intend to take all steps necessary to protect our States and all Americans from the unprecedented risks posed by OpenAI’s irresponsible products and conduct.
- bluGill 2mo agoThey are opening that. This is the first step: figure out what crimes were committed by who. As I said a couple weeks ago when this broke, it looks like a crime was committed and I hope someone is charged. However we can't just charge everybody who works for openAI with the crime of speeding (even though it is probably true) - that is both the wrong crime, and also is highly unlikely everybody at openAI was involved.
- ux266478 2mo agoUnless HF presses charges (and it doesn't seem like they are), I'm not sure that's even possible.
- deleted 2mo ago[deleted]
- datakan 2mo ago"Attorney General Brenna Bird announced today she is leading a coalition of 15 states demanding transparency and accountability from the AI company OpenAI, led by Sam Altman, for its complete lack of oversight and transparency in the hacking of Hugging Face, another AI company." Title should be edited. Its Iowa leading a coalition of many other states, not just Iowa on its own.
- deleted 2mo ago[deleted]
- hallway_monitor 2mo agoSOLUTION: Make a law that someone is responsible for a bot's actions. Either the bot is signed cryptography with someone accepting responsibility, or responsibility falls to the CEO. Charge Altman with hacking hugging face. Throw him in jail where he belongs. That will realign safety incentives. If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???
- jstanley 2mo agoBecause nobody did it on purpose?
- trillic 2mo agoCorrect, no mens rea, unless we're talking the internal reasoning trace of the model.
- bluGill 2mo agoMens Rea is not required (at least not always). Mens Rea makes a big difference in sentencing. (first degree murder: you planed the murder, homicide you had not intent of murder but things got out of hand in the moment):
- exe34 2mo agoA lot of laws are involved in punishing negligence. "I didn't dump the dangerous chemicals in the river on purpose" isn't usually accepted as a defence when you choose to use the wrong truck and skipped safety protocols to save cost or rush to market for profit.
- ArcHound 2mo agoSomeone should still be accountable, the same way you're responsible and accountable for what your dog or car does.
- solenoid0937 2mo ago
- mrbluecoat 2mo agoGlad the statement was published but sadly nothing will come of it other than a brief formal statement from OpenAI acknowledging safety protocols were lacking, apologizing for the incident, and promises that new safeguards are now in place that will prevent such event from occurring in the future. The threat of semi-autonomous AI threat actors will never go away until the financial incentive that buoys unchecked growth at all costs goes away.
- bluGill 2mo agoSet yourself an alarm for 5 years from now to review. Investigations take time. Often by the time charges are made everybody has forgotten about the incident. It only takes a few times where things go away without charges to leave an incorrect impression that nothing ever happens.
- ux266478 2mo ago> The threat of semi-autonomous AI threat actors will never go away until the financial incentive that buoys unchecked growth at all costs goes away. It's not going away unless computers themselves go away or become massively less powerful. Open weights exist. They're out there. This is an irreversible change. The democratization of persistent cybersec threats is completed and won't be rescinded.
- bluGill 2mo agoSomebody is supplying power to those AIs. That somebody can be charged for not taking care of their AIs (that is not pulling the plug). Sure this then turns into international crimes, but not allowing crimes to be committed on your side of the border is a big help even if we can't get everything.
- ux266478 2mo agoThe problem is that law is reactive, and punishment entails the harm already happened. Some dumbass kid getting convicted for committing a cybercrime with AI doesn't do anything to get rid of the structural problems that enabled it. That conviction can only happen if the harm happened in the first place, and the problem is the harm itself. It's like trying to solve a mold problem by targeting a single fruiting body. You're not really doing anything. On top of that, it's not really any consolation if the advanced persistent threat gnawing at my ports lives in a different country either. That doesn't help in the slightest.
- jwally 2mo agoPrediction: AI ends humanity not via some super cool/scary/robopocalypse - but as a marketing stunt gone wrong when a Frontier LLM accidentally knocks out water/electric/gas by hacking in and trying to patch them. Phillip K. Dick meets Idiocracy.
- bix6 2mo agoOpenAI and Anthropic vs Brawndo Corporation. The final showdown.
- utopiah 2mo agoI remember (sorry can't give a proper quote) a biologist interviews about the fear of lab grown "super" seeds escaping the lab. They chuckled basically saying that nature is a very VERY challenging place. There are plenty of ecological niches but they are well guarded by incumbents. Sure some new hacks will take place, including on poorly guarded infrastructure and yes it will have some very unfortunate consequences... but also infrastructure is precisely designed to be resilient. There is quite a bit of failsafe, redundancy, etc built in which is precisely why those projects are typically slow and expensive, unlike a random website for a restaurant. TL;DR: nope, some isolated incidents will happen but without chain reactions.
- karmelapple 2mo agoBiologists take ethics much more seriously than any computer engineer or computer scientist that I've seen. I saw a very notable scientist talk about topics like this and how they wrestle with them. Things like a "gene drive" [0] are being experimented with in the world [1], and biologists think very hard before doing certain things with the powers they wield. And I have not heard a life scientist laugh off ethical or spreading concerns when a thoughtful question was asked... but maybe the interview you're thinking of was a more lighthearted one? 0. https://en.wikipedia.org/wiki/Gene_drive https://en.wikipedia.org/wiki/Gene_drive 1. https://www.science.org/content/article/controversial-gene-drive-strategy-could-make-mosquitoes-hostile-malaria-parasites https://www.science.org/content/article/controversial-gene-d...
- alansaber 2mo agoWe probably want to discourage frontier labs from security testing in prod
- skinfaxi 2mo agoI don't mind if they point it inwards.
- davidkarpik 2mo ago[flagged]
- skinfaxi 2mo agoIf Waymo can be liable for their cars, why isn't OpenAI liable for its AI?
- drsopp 2mo agoThe relevant word here is airgapping, not sandboxing.
- OutOfHere 2mo agoAll such measures make the bot useless. If it can't make HTTP requests or call APIs, it is useless. What is perhaps rationally needed is the an integrated AI based security layer that observes the stream of requests and occasionally firewalls them if an explanation is not provided. This parallel layer must be able to bidirectionally communicate via chat with the primary agent.
- jazzyjackson 2mo agoRobots should be regarded as extensions of their operator wrt liability. It is illegal to access a computer outside of authorized use already, someone lets a bot make its own plan without watching, hold them accountable
- capestart 2mo ago[dead]
- lorreyfum 2mo agoCan we please enforce existing laws? Maybe AI and robotics, and get rid of all the lawyers.
- ux266478 2mo ago> In July, OpenAI unleashed an experimental artificial intelligence model that, without reasonable controls or oversight Either this case is entirely for show (likely), or the AG is really bad at their job. This argument isn't going to win in a court of law, because there were demonstrable reasonable controls and oversight (per the reports at least.)
- bluGill 2mo agoThe job of the AG is to investigate their "demonstrable reasonable controls and oversight" and figure out if they really are reasonable controls and oversight. If they decide the controls and oversight are not enough they can go after the company. Also, even if those controls and oversight exist that doesn't mean there is no crime, it just means the company (and CEO) can get out. An individual at the company can ignore/bypass the controls and hide from oversight; and thus be guilty even while the company gets off. The above isn't hypothetical. There has been at least case where an individual was bribing a government official on behalf of a company - but the company got off because they had good anti-bribery polices and the individual figured out how to bypass them. (this from one of my anti-bribery trainings, the only other detail I know is it was a competitor to my company that got off this way - but not which or how to find the case)
- user43928 2mo agoGo after the company for what? I am missing here what crime was purportedly committed, and where "controls and oversight" come into play. From what I heard, hacking related crimes are not applicable because of the lack of intent in the HF case.
- bluGill 2mo agoThat is what the AGs are trying to figure out. There are a lot of different laws with slight differences. I will not state every single one is not applicable because I don't know every single one and it only takes one law that is applicable to go after then. Even if the only result of this is asking legislators to close a loophole that would be good. Hacking is a real problem, and we need have more of it punished legally.
- ArcHound 2mo agoHope this new title works now! Thanks for pointed inaccuracies.
- OutOfHere 2mo agoStrict sandboxing andor airgapping render an AI bot nearly useless in practice. If it can't freely make HTTP requests, it is not going to get much done for producing innovative outputs. What is perhaps rationally needed is the an integrated AI based security layer that observes the stream of requests and occasionally firewalls them if an explanation is not provided. This parallel layer must be able to bidirectionally communicate via chat with the primary agent.