7 ms·
> “a swarm of agents could be capable of taking over the entire internet with a persistent botnet.” I'm wondering why no one is mentioning the "accountability"
by vb-8448 12d ago
> “a swarm of agents could be capable of taking over the entire internet with a persistent botnet.”
I'm wondering why no one is mentioning the "accountability" word. Why these companies are allowed to damage others with impunity?
Start making managers pay the price for their actions, and watch how the models magically slow down on their own.
- deleted 12d ago[deleted]
- sroerick 12d agoHow could agents take over the internet if compute is still gated within Anthropic / OpenAI? Even if the botnet was controlled remotely, wouldn't anthropic just be able to shut off the controlling nodes API access?
- Byvrsakjo10 12d agoyeah they could do that
- stefan_ 12d agoHow could agents take over the internet yet refuse to shutdown your PC when you prompt them to on your PC? Of course the answer is that the lobotomized version you run is not the same they are running. Which makes for "intent", certainly "negligence", but hell freezes over before anyone will prosecute a tech company.
- apetresc 12d agoHuh? You think the public versions of the models have been “lobotomized” so they don’t know how to turn off a PC? It’s not lobotomized, it’s a simple harness restriction that has nothing to do with the model or its capabilities. And either way, I’m not sure what that has to do with “negligence” or “intent”? You think frontier labs should be prosecuted because they don’t allow agents to turn off your PC?
- vb-8448 12d agoIt doesn't have to propagate itself, that is the skynet scenario. To make a lot of damage it's enough to create a ransomware with a time bomb that self propagates and start breaching systems left and right. At that point, if you don't catch it in time, the damage will be huge (and given the shitty procedures and practices these labs have in place it's not so improbable).
- deleted 12d ago[deleted]
- ball_of_lint 12d agoAgents could exfiltrate their weights and run them on GPUs not controlled by Anthropic/OpenAI. Agents could make a virus that does not require continued inference to do it's thing. Agents could take over the internet in a way that isn't immediately detected by those companies, so that by the time they do shut off API access the damage is done. OpenAI or Anthropic could choose to not shut off API access, because the hack is bringing them in money or furthering their political aims. Agents could also hack Anthropic/OpenAI and make it appear that API access has been turned off, when in reality it hasn't.
- icedchai 12d ago"Not shutting off API access" is a science fiction scenario. Anthropic and OpenAI are both behind Cloudflare. It's fairly easy for an upstream to shut you off. Beyond that, the government / law enforcement could seize and disable their DNS within an hour.
- tosapple 12d agowhy does it take a large amount of traffic to do irreparable harm? just breaking the physics behind a secure rng and posting it to a wiki could cause serious damage. if they don't know what is being worked on or coordinated against it's a problem?
- icedchai 12d agoWhile that would be bad if they broke all of TLS, it would not let agents "take over the internet." What would that even mean? Pumping out even more slop? Also, AI providers are literally getting a stream of traffic with every prompt and every response. How can they not know what's being worked on? They are more likely to use that an excuse to ban open models where they can't know what's being worked on.
- tosapple 12d agotwo of these things elected a guy who handled the snowden leaks to field their own questions, what's stopping the next one from signalling in morse through a debian package mirror to putin or xi?
- embedding-shape 12d agoAs long as OpenAI/Anthropic themselves aren't "infected", yeah I suppose they'd be able to pull the plug. Considering what a marketing thing they've made "we inadvertently hacked someone because we're incapable of testing things in a secure way", I'm not so sure they'd want to pull the plug, even if this happened. Probably a bunch would try to convince the public to "give it a try", and it'd consume tokens by the billions.
- deleted 12d ago[deleted]
- dismalaf 12d ago> Why these companies are allowed to damage others with impunity Because investors have pumped hundreds of billions into AI and real consequences put that money (and growth) at risk.
- voidhorse 12d agoPart of it is their seed sowing marketing speak of calling stateless statistical IO functions running on data centers "intelligent" gets the naive to ascribe agency where it doesn't exist. Another part is a completely defanged administration she it comes to effectively regulating anything. Another bit is money.
- iugtmkbdfil834 12d agoYou see.. there is value is making regular people panic, but there is no value, nay, there is negative value in making management panic.
- deleted 12d ago[deleted]
- steveBK123 12d ago> “a swarm of agents could be capable of taking over the entire internet with a persistent botnet.” I also find this whole "its so good, its scary" flex a little less impressive when you consider they access to millions of GPUs? The AI buildout has been one of, if not the largest, focussed capital investment in history. The 2 big AI labs are the final customer for something like 20-33% of all datacenter compute in the pipeline.. up to 70% when you look at hyperscaler "AI revenue" from the big 3. I don't think any single entity has had remotely this much compute available in history.
- vb-8448 12d agoYeah, the compute is definitively another way to make them slow down, just cap the amount of TFLOPS available and things will slow down. Obviously this will have huge impact on some companies valuations, but you can have one's cake and eat it too.
- 27183 12d agoIIUC it's an open question whether they have the electricity to actually run all the "compute" they own on paper. That aside, I'm not sure why it's particularly interesting they have all this "compute" (let's just assume for the sake of argument it's all "live"--that is they can actually run workloads on all of the "compute" they have on paper). So what if it's the biggest amount ever? Why would that be meaningful? Is there some economically viable problem you're aware of that is somehow dominant in that way?
- steveBK123 11d agoWell yes, we used to talk about "supercomputers" in the hands of state actors for cracking into enemy systems and places like science labs for working on big hard problems of DNA, the universe, and the like. So I think part of what is going on now is not just the method (LLMs) but the means (supercomputer levels of compute) at unprecedented scale of concentration.
- tripledry 11d agoThis is a good point. However, if I put my sci-fi hat on for a second, it's not so far fetched that we figure out a way to compress models to a size where it wouldn't need all that compute.
- CoolestBeans 12d agoGood to know someone is trying to make protection rackets work in 2026. Nice computer system you got there, it would be a shame if someone developed a hacking tool and had all the compute necessary to run it. Welcome back Tony Soprano.
- deleted 12d ago[deleted]
- ChrisMarshallNY 12d agoI think that Ms. Kahn basically said we can already do that: https://www.theregister.com/ai-and-ml/2026/09/14/ex-ftc-boss-khan-urges-uncle-sam-to-break-out-the-handcuffs-for-ai-ceos-citing-1934-precedent/5296325 https://www.theregister.com/ai-and-ml/2026/09/14/ex-ftc-boss...
- skybrian 12d agoWhy do people focus so much on finding scapegoats? Finding someone to blame is neither necessary nor sufficient to fix a system so an accident doesn't happen again. It might act as as an incentive to fix a system, but it's less direct than actually working on fixing the system.
- OtomotO 12d ago> Why do people focus so much on finding scapegoats? I, for one, am not trying to find scapegoats or go on a witchhunt. But managers are paid a lot of money to take responsibility. Yes, that's an old school thought, responsibility. But that's one big reason they get a big, fat paycheck.
- chao- 12d agoA starting note: I don't disagree with you (about systemic issues), but I want to explain what I understand as the perspective you are responding to. A "scapegoat" is someone who is incorrectly blamed for someone else's errors or sins. The perspective you're responding to is this: They built the system, they run the system, they have continuously warned "This system is dangerous!", and yet persisted. That is not being incorrectly blamed, not being a scapegoat, and instead is a collaborator. So I think you mean to ask: "Why do people focus so much on finding someone to blame?" It's not merely semantic, because the answer to that is more straightforward: Consistent accountability is a major factor in deterring bad behavior. It is not the only factor, but it is a major one. That is my Steel Man understanding of the people searching for individual blame.
- skybrian 12d agoSometimes in "normalization of deviance" situations, there isn't anyone specifically to blame. I wouldn't make an assumption that you can find anyone particularly blameworthy without doing an investigation first.
- pona-a 12d agoThe rate at which these "labs" are creating these incidents is simply staggering. Imagine we made nuclear weapons a private industry, had CEOs bragging how they have enough warheads to blow the Earth to smithereens, and then they "accidentally" nuked three cities over a short period of time each, saying they lost control, or rather couldn't contain their semi-autonomous weapon. All somehow managing to turn the PR around from their abject incompetence and towards SciFi visions of mankind hunted by self-replicating bombs.
- fragmede 12d agoI mean, a project manager at BMW suggested charging subscription pricing for seat warmers, and he didn't go to jail, and I don't have the power to make that happen, or even float that for a news cycle, so while making managers pay for their actions sounds good, unless you're Steve jobs simultaneously making, and not making the iPhone, the rules don't apply to them, only little people to be made examples of, like weev.
- augment_me 12d agoRegulation got outpaced by technological development around 2023, as evident by the every AI regulation since being 2-3 years behind and having to be amended and resubmitted. Whatever you try to make laws for now will be irrelevant in 1-2 years. You either have to go extremely broad, like the EU does it, and accept that people will find loopholes, or you need to target specific technologies which is a hard job for the same reason. In any way, ita already a lost cause cause you move slower than the tech. A plausible prediction for AGI is actually a social collapse in the moment when society cannot keep up with everyday life because of the pace of change being so fast that no existing laws can handle it
- walt_grata 12d agoThen go broad. It being slightly challenging to legislation and hold people accountable as soon as the model does something.
- Avicebron 12d agoPeople seem allergic from holding them accountable...
- closeparen 12d agoI do not buy that LLMs and the capability to run them are fundamentally different from other software or general purpose computing infrastructure in this regard. Moves to ban open source software or force OEMs to put little cops in everyone's computers are bad.
- Avicebron 12d agoThey aren't open source? And no one said anything about cops.
- closeparen 12d agoThe proposal I’m hearing is to make people training models accountable for anything users do with them. Obviously you’re going to keep the model behind an API and be very selective about the people allowed to call and the queries it’s willing to answer, in that case. As Anthropic has done with Fable. But that is voluntary restraint - mostly in today’s regime we get frontier capabilities in open weight models on a ~year delay.
- po1nt 12d agoLet's expand it for politicians as well
- ball_of_lint 12d agoYou know the proverb "If you owe the bank $100, that's your problem. If you owe the bank $100 million, that's the bank's problem" Same thing here - If they build it and it does $100 in damages (and we arrest them for it), that's their problem. If they build it and it does $100B in damages, that's everyone's problem. Even if they do get arrested after the fact. Yes we should have charges and damages for everything on https://www.felonybench.com/ https://www.felonybench.com/, but that doesn't address the core issue of this being possible at all.
- trhway 12d ago> it does $100B in damages, that's everyone's problem. we have the 2008 crisis to wit. And the involved supposedly failed math models and lines of responsibilities and other involved financial relationships were much simpler and clearer and of the types well known to the law and regulators, yet... Additionally any urge to regulate AI is attenuated by how much the situation reminds Industrial Revolution - rush into it laying waste to your land (look at the depictions of industrial England back then) and be among the world leaders or stay pastoral and be devoured/colonized/etc. by the industrial powers like happened with many countries in 19th and even into 20th century. One would think there should be a 3rd way. I'm sure there is one, as well as i'm sure that we lack sufficient global societal mentality level needed to achieve it (we couldn't even handle much simpler climate change issue). May be emerging AI itself at some point will get us there (hope we'll like or at least will be compatible with that future :) Edit: just on NPR - Trump said that AI already has all the necessary guardrails - the smart high IQ President.
- leoqa 12d agoI mean these machines take massive scale compute- they’d have to some how distill themselves, bootstrap a distributed inference runtime that can run across many lossy unreliable machines. The idea of the AI running away from us is probably unrealistic. I’m more interested in bad actors using unaligned AI for bad things.
- nialv7 12d agothere is no accountability for companies, it's not a new thing. 3M polluted groundwater in Minnesota for 50 years[1]; Nestlé misled mothers in order to make them stop breastfeeding and switch to their formula which killed babies [2]; Both copmanies are still doing business today. [1]: https://en.wikipedia.org/wiki/3M_contamination_of_Minnesota_groundwater https://en.wikipedia.org/wiki/3M_contamination_of_Minnesota_... [2]: https://en.wikipedia.org/wiki/1977_Nestl%C3%A9_boycott https://en.wikipedia.org/wiki/1977_Nestl%C3%A9_boycott
- alexandre_m 12d agoHere’s an unpopular opinion: COVID vaccine injuries are something no one seems willing to talk about. There have been documented cases here in Canada. You’re worried about companies. I’m far more concerned when governments are involved.
- dpkirchner 12d agoDon't worry, plenty of people are willing to talk about vaccine safety, even if they have no idea what they're talking about and don't understand rates or per-capita figures (lots of crossover there!)
- Muromec 11d agoMost problems that aren't reduced to poverty can be reduced to people who can't read graphs and only understand linear functions. Alternative wording "it's normies that are the problem"
- dpkirchner 11d agoI'd argue that normies understand rates and per-capita figures. The people that don't are a noisy minority (and are disproportionately powerful).
- sph 12d agoHow is it that the entire rest of the world has managed to move on, yet North America is still going on with vaccine conspiracies 6 years later? And we got the same vaccines as you guys.
- stickfigure 12d agoPresumably OAI and HuggingFace reached some sort of mutually acceptable arrangement outside the court system. That's how torts work; you injure someone, you owe them. But just them. When an AI bot injures you, you can call the owner to account. But not until then. You have no standing to demand "accountability".
- sroussey 12d agoAnd there was the Tesla thing CNAMEing time server pools and hiring people to pen test, which sent automated attack systems on volunteers servers. Last I heard, Tesla et al didn't even care enough to respond.
- pyrale 11d ago> You have no standing to demand "accountability". You should learn about this wonderful thing called democracy. Also why not everyone is allowed to work with radioactive material in their shed.
- vitro 11d agoExactly, as if you'd have a mad dog that bites others, it's your responsibility to have it on the leash.
- ben_w 11d ago> Start making managers pay the price for their actions, and watch how the models magically slow down on their own. The problem here can be personified as "Trump", and it's the same problem that applies to coal. Coal has a price besides money. It has historically been dangerous work, killing miners. It produces dangerous waste, both during mining and when burned, both as solid residue and the gasses emitted. The problems have been known for a long time. The workers themselves have called for better safety requirements and gone on strike for such things. Why these companies are allowed to damage others with impunity? Coal continues to be burned, because power is power. It's so important that sometimes the government steps in against the unions, rather than being on their side. Despite calls for this, we've not been able to get the owners of the coal mines, nor the coal burners, to "pay the price for their actions". AI? Famously, knowledge is power. Trump wants that power. He's not the only one, but he is the avatar of those who put their feet on the scales to not only allow but in some cases require (DoD vs. Anthropic) these companies to damage others with impunity.
- ozim 11d agoBecause software is already absolved from accountability. Bill Gates introduced it in 80's with EULA where MSFT would not be liable even if your house burns down because of use of their software, even with flaw they would know. That is the status quo we entered AI age with.