Fully autonomous AI agents should not be developed
huggingface.co
huggingface.co
ICML25 has an explicit call for position papers: https://icml.cc/Conferences/2025/CallForPositionPapers
Shouldn’t we treat separately autonomous agent we write ourselves, or purchase to run on our own computers, on our own data and that use public APIs for data?
If Margaret is reading this thread, I am curious what her opinion is.
For autonomous agents controlled by corporations and governments, I mostly agree with the paper.
in this paper, it's clear that the authors don't think modern LLM-based systems are just stochastic parrots.
If we only handle AI that well doom is probable. It has economic uses, unlike nuclear weapons, so there will be a thriving black market dodging the safety concerns.
Also there are only a few companies that can fab the semiconductors needed for these training runs.
It is also quite possible for our society to decide that deep learning is too dangerous and to outlaw teaching and publishing about it, which would not completely stop the discovery of algorithmic deep-learning improvements (because some committed deep-learning enthusiasts would break the law) but would slow the discovery rate way, way down.
And most people who think AI "progress" is so dangerous that it must be stopped before it is too late have loose confidence intervals extending for at least a couple of decades (as opposed to just a few years) as to when it definitely becomes too late.
Unless the first one is so advanced no other can challenge it, that is.
Humans have prevented it many times, but not specifically by technological ability. If Putin/Trump/Xi Ping wanted a global nuclear war, they'd better have the means to launch the nukes themselves in secret because the chain of command will challenge them.
If an out-of-control AI could discover a circuitous way to access nukes, an antagonist AI of equal capabilities should be able to figure it out too, and warn the humans in the loop.
I agree that AI development should be made responsibly, but not all people do, and it's impossible to put the cat back in the bag. The limiting factor these days is hardware, as a true AGI will likely need even more of it than our current LLMs.
The thing with autonomous AI is that we already know it cannot be made safe in a way that satisfies lawmakers who are fully informed about how it works… unless they are bribed, I suppose.
There's no mention of externalities. That is, are the costs of AI errors borne by the operator of the AI, or a third party.
> • Simple→Tool Call: Inaccuracy propagated to inappropriate tool selection.
> • Multi-step: Cascading errors compound risk of inaccurate or irrelevant outcomes.
> • Fully Autonomous: Unbounded inaccuracies may create outcomes wholly unaligned with human goals.
Just... lol
create code(user request);
execute();
Is this not possible with tool use alone, so long as the agent has access to a tool that can execute arbitrary code?
Imagine if the A-bomb was being openly developed. What title would have contributed more to funding and research, "The A-bomb (is terribly powerful and) should not be developed" or "The A-bomb will never work"? Except the A-bomb did work and in a surprisingly short time, while autonomous AGI is still a conjecture.