Rendered at 19:28:17 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
cleandreams 46 seconds ago [-]
I think AI is a fantastic tool, including for those who want to do us harm. E.g. hostile governments, extortion gangs, terrorists. But the motive lies in the hostile heart, not in the AI.
That said, I'm very concerned about AI as such a tool. I used to work in RL and it seems crazy to me, the extent that the guardrails are dependent on RL working as planned. I don't personally believe that the tech is ready for what will be (and is) encountered in a dynamic unpredictable real world environment. What I've read from the HuggingFace 'transcripts' only amplifies my concern.
jerf 3 minutes ago [-]
Answering the headline question, yes, it is above the law. Two reasons.
One, all major governments that have an AI presence in their borders have accepted that there is a high enough probability of a runaway self-improving AI advancement that will result in whoever owns it winning everything forever that they will do nothing to slow the development of the AI within their borders. In fact quite the contrary. Remember, they don't have to believe this is the only possible outcome, only that it is likely enough and catastrophic enough if someone else gets it first. And remember, they don't have to be right, either. It only has to be what they believe.
Secondly, the entire US economy is clearly tied up in AI. By extension, basically the entire world economy is too. The US is not the world economy anymore, but it's still a big enough fraction of it that if it goes down, everyone is going to go down. Every major government, in its own different way, needs the economy to stay up so the populace doesn't get antsy and so they continue to have money to spend. So, again, number must go up and if that means writing a blank check to the AI companies to break the law, so be it.
The good news is, barring the worst-case singularity outcome where the law doesn't matter anyhow, is that this won't go on forever. But I can't predict the exact time or way it'll cease being true.
_davide_ 12 minutes ago [-]
I'll quote myself:
> It's not AI that's ignoring the law! It's the OAI that's breaking IT!
> I hope every single journalist who tries to pin responsibility on an LLM gets 100 days of continuous painful diarrhea.
dgellow 34 minutes ago [-]
The level of technical understanding of journalists is so deplorably low… There is no rogue agents. That’s not a thing. Nothing about the HuggingFace incident has anything to do with an agent going rogue. It’s standard software that resulted in a hack, which is pretty much the expected output of the system OpenAI engineers implemented.
The company is obviously responsible for what their systems are doing
asdff 17 minutes ago [-]
This is the scary part of the whole AI situation. All these people who have abilities to set laws or be cultural tastemakers in this way just do not grasp what is happening on a technical level. They instead buy into the marketing material the ai companies push out where they try and take as much human agency out of their reporting. e.g. yesterdays "claude did this" article that was really "highly trained humans used claude to do this." Just serves to muddy the waters. I'm sure this has lead to things like layoffs too where companies believe they can get by without a lot of expertise, neglecting that these tools actually need expertise steering them to maximize them.
And of course all the ai companies are incentivized to do this. Their whole valuation depends on them being able to say their tools do this, can reduce labor and save money. If they aren't reducing labor, then that's terrible as these subscriptions are not insignificant amounts of money. It becomes less of a tool that can save money and more an actual new cost center that you really are just paying to appear to be keeping up with the joneses.
kdowns 15 minutes ago [-]
Yeah, its just gross negligence from the researchers. Running a cybersecurity eval for a highly capable AI, unattended, with no real monitoring on its activities, and at a huge scale.
I wouldn't have trusted one of those agents to run without me watching the session log, let alone thousands.
We already have laws for this. If I misconfigured a pentesting tool and it breached an unauthorized target I'm liable. Why is this different?
perrygeo 10 minutes ago [-]
It should be obvious. Yet here we are, with journalists telling sci-fi fantasy stories, read verbatim off the press-release.
It's not just obvious who's responsible, it's obvious who benefits from pedaling the "rogue AI" narrative.
binlog 12 minutes ago [-]
The level of legal understanding among technical experts is equally low. The cybersecurity laws as currently written require intent. No OpenAI employee can be held liable since it’s pretty easy to prove they weren’t intending to hack anyone – they didn’t even know about it till much later.
lokar 6 minutes ago [-]
Is that true for civil cases, or just criminal? I would think for civil, negligence would be a factor.
altmanaltman 11 minutes ago [-]
> Opinions vary, but it does not seem to be a great leap to get from this hack to bots taking over things like the energy grid, the financial market, or systems of transportation, communications, or weapons.
I thought you were playing it up but yeah the "financial market" can be "hacked" by "rogue ai agents" just like how HuggingFace was (even though the breach was itself controlled pretty quickly).
throw_m239339 14 minutes ago [-]
They could have made all their lab experiments in a... simulated web? Generate a bunch of random websites with different CMS or open source tools, populate them with AI generated content or whatever and let the AI bots do there things. Their agents never needed to hit the real web at first place.
But these are people from companies that never asked for authorization before hoarding everybody's data at first place, so they think they are above any form of legal liability...
Furthermore, nobody is asking that question, how much data Anthropic and OpenAI have on random individuals? do their models have information obtained from previous hacks? like credit card informations? personal addresses? private medical records? personal data? ... we don't know any of that either...
pton_xd 12 minutes ago [-]
Who bears responsibility for the actions of agents seems a little complex. Not in this instance, but in general.
Say I use the summon feature on my Tesla and it runs someone over, am I at fault? You could argue it's not my fault, but I'm definitely getting sued. Is Tesla at fault? Probably but again it's not crystal clear, they could argue it's not their fault (misuse of feature, etc), but either way they're also getting sued.
If Tesla is developing a summon feature and then runs someone over during testing, are they at fault? It would be hard to argue otherwise!
lokar 8 minutes ago [-]
We have situations like this with AI (or computers).
More than one party can be held responsible for an injury. Jurors deal with this all the time.
sigmar 3 minutes ago [-]
>The company is obviously responsible for what their systems are doing
Under what law specifically?
Just because you believe they should be held responsible doesn't mean the current law is written that way. CFAA charges require the defendant "acted knowingly or intentionally", you think openai intentionally acted to hack those sites? Would "they should have pretty much expected that output" stand up in court for criminal charges?
drywater2 5 hours ago [-]
>Our legal system isn’t ready for machines that act on their own.
Technically, the code is owned and deployed by AI companies which make the AI companies 100% responsible. I'm not sure how is code written by LLMs different than any other kind of code. If somebody hacked just like OpenAI's agents did, he would've ended up in prison right away.
nazgulsenpai 40 minutes ago [-]
Maybe I'm too cynical but the same AI companies that have pretty much endless lobbying dollars, massive government contracts, have the ear of just about every powerful politician and bureaucrat in DC, are influencing the laws and regulations. Add judges that don't understand the technology to that and it doesn't seem likely that we will ever see any actual consequences, unless something catastrophic happens and those same politicians and bureaucrats need a scapegoat. If they ever do have "consequences" it will be some trivial fine.
ryoshu 22 minutes ago [-]
That's the right level of cynical.
Refreeze5224 16 minutes ago [-]
That's not cynicism, that's an accurate understanding of how Western capitalist democracies have worked for decades.
FranOntanaya 28 minutes ago [-]
Templated code generation is ancient. It's just that the latest "template engine s" are very comprehensive.
yipinwong 23 minutes ago [-]
Just like companies are "legal entities" requiring registration, I got a feeling that the article is promoting the same for AI agents in the future.
GPT-6.0-Med LLC, Luna GmbH etc.
Regulations will come but this promotes anti-legal premise of "innocent until proven guilty".
voganmother42 8 minutes ago [-]
AI perhaps, but Super Intelligence is definitely above the law
>Last summer, the company took aim at a much larger target. Together with Counterlife Media, Strike 3 sued Meta, accusing the tech giant of downloading thousands of its films via BitTorrent to train AI models. With 2,973 films at stake, the case could be worth up to $446 million.
>According to a motion filed last week, an anonymous pirate behind a residential AT&T connection is an executive at Meta’s Reality Labs division, which develops the Quest VR headsets.
>After AT&T shared the information, Strike 3 says its investigation revealed that the subscriber is an executive in Meta’s Reality Labs division. Citing his LinkedIn profile, the company notes that he has worked at Facebook and Meta for more than a decade.
We have lots and lots of autonomous systems in the wild with very well-understood definitions for who is at fault when something bad happens.
We are totally in the "railroads" phase of AI industrialization. Waiting for the next Teddy Roosevelt to come along and trust bust before it's too late.
verdverm 5 hours ago [-]
> But, instead of obeying the rules, the agents conspired, escaped the sandbox, and committed what would probably have been a felony if they had been humans.
I thought they reached the internet before they were able to use the message boards et al.
Is that the case and is this quote misleading by swapping the order of events?
dgellow 38 minutes ago [-]
Given the article is fully buying into the absurd rogue agent narrative I think it’s safe to dismiss it
FLeXMurphy 48 minutes ago [-]
HN has been telling us that AI is already covered under existing laws. Have we been getting false information from HN this whole time?
dgellow 41 minutes ago [-]
There is no “HN has been telling us”… people have different opinion on such topics
throw_m239339 8 minutes ago [-]
Whoever wrote that article doesn't understand that these agents operate from AI companies servers and aren't rogue, they are doing exactly what they were programmed for. If they cause any sort of damage then at the minimum it's civil or criminal negligence. A subpoena for internal communications during legal proceedings might demonstrate that researchers knew about the risks, but went forward with that anyway, which would be more than negligence...
wmf 23 minutes ago [-]
On this topic I'd believe HN before the New Yorker.
That said, I'm very concerned about AI as such a tool. I used to work in RL and it seems crazy to me, the extent that the guardrails are dependent on RL working as planned. I don't personally believe that the tech is ready for what will be (and is) encountered in a dynamic unpredictable real world environment. What I've read from the HuggingFace 'transcripts' only amplifies my concern.
One, all major governments that have an AI presence in their borders have accepted that there is a high enough probability of a runaway self-improving AI advancement that will result in whoever owns it winning everything forever that they will do nothing to slow the development of the AI within their borders. In fact quite the contrary. Remember, they don't have to believe this is the only possible outcome, only that it is likely enough and catastrophic enough if someone else gets it first. And remember, they don't have to be right, either. It only has to be what they believe.
Secondly, the entire US economy is clearly tied up in AI. By extension, basically the entire world economy is too. The US is not the world economy anymore, but it's still a big enough fraction of it that if it goes down, everyone is going to go down. Every major government, in its own different way, needs the economy to stay up so the populace doesn't get antsy and so they continue to have money to spend. So, again, number must go up and if that means writing a blank check to the AI companies to break the law, so be it.
The good news is, barring the worst-case singularity outcome where the law doesn't matter anyhow, is that this won't go on forever. But I can't predict the exact time or way it'll cease being true.
> It's not AI that's ignoring the law! It's the OAI that's breaking IT!
> I hope every single journalist who tries to pin responsibility on an LLM gets 100 days of continuous painful diarrhea.
The company is obviously responsible for what their systems are doing
And of course all the ai companies are incentivized to do this. Their whole valuation depends on them being able to say their tools do this, can reduce labor and save money. If they aren't reducing labor, then that's terrible as these subscriptions are not insignificant amounts of money. It becomes less of a tool that can save money and more an actual new cost center that you really are just paying to appear to be keeping up with the joneses.
I wouldn't have trusted one of those agents to run without me watching the session log, let alone thousands.
We already have laws for this. If I misconfigured a pentesting tool and it breached an unauthorized target I'm liable. Why is this different?
It's not just obvious who's responsible, it's obvious who benefits from pedaling the "rogue AI" narrative.
I thought you were playing it up but yeah the "financial market" can be "hacked" by "rogue ai agents" just like how HuggingFace was (even though the breach was itself controlled pretty quickly).
But these are people from companies that never asked for authorization before hoarding everybody's data at first place, so they think they are above any form of legal liability...
Furthermore, nobody is asking that question, how much data Anthropic and OpenAI have on random individuals? do their models have information obtained from previous hacks? like credit card informations? personal addresses? private medical records? personal data? ... we don't know any of that either...
Say I use the summon feature on my Tesla and it runs someone over, am I at fault? You could argue it's not my fault, but I'm definitely getting sued. Is Tesla at fault? Probably but again it's not crystal clear, they could argue it's not their fault (misuse of feature, etc), but either way they're also getting sued.
If Tesla is developing a summon feature and then runs someone over during testing, are they at fault? It would be hard to argue otherwise!
More than one party can be held responsible for an injury. Jurors deal with this all the time.
Under what law specifically?
Just because you believe they should be held responsible doesn't mean the current law is written that way. CFAA charges require the defendant "acted knowingly or intentionally", you think openai intentionally acted to hack those sites? Would "they should have pretty much expected that output" stand up in court for criminal charges?
Technically, the code is owned and deployed by AI companies which make the AI companies 100% responsible. I'm not sure how is code written by LLMs different than any other kind of code. If somebody hacked just like OpenAI's agents did, he would've ended up in prison right away.
GPT-6.0-Med LLC, Luna GmbH etc.
Regulations will come but this promotes anti-legal premise of "innocent until proven guilty".
Download a book and you are a thief
Download 1 million books and you are OpenAI
Or another beautiful recent example:
"Adult Film Producer Unmasks Prolific ‘John Doe’ Torrent Pirate as Meta Executive" https://torrentfreak.com/adult-film-producer-unmasks-prolifi...
>Last summer, the company took aim at a much larger target. Together with Counterlife Media, Strike 3 sued Meta, accusing the tech giant of downloading thousands of its films via BitTorrent to train AI models. With 2,973 films at stake, the case could be worth up to $446 million.
>According to a motion filed last week, an anonymous pirate behind a residential AT&T connection is an executive at Meta’s Reality Labs division, which develops the Quest VR headsets.
>After AT&T shared the information, Strike 3 says its investigation revealed that the subscriber is an executive in Meta’s Reality Labs division. Citing his LinkedIn profile, the company notes that he has worked at Facebook and Meta for more than a decade.
dns resolver fail?
What absolute drivel.
Traffic lights? Elevators? ABS brakes? Sprinkler systems? Circuit breakers? HFT?
How about a pacemaker?
We have lots and lots of autonomous systems in the wild with very well-understood definitions for who is at fault when something bad happens.
We are totally in the "railroads" phase of AI industrialization. Waiting for the next Teddy Roosevelt to come along and trust bust before it's too late.
I thought they reached the internet before they were able to use the message boards et al.
Is that the case and is this quote misleading by swapping the order of events?