Hugging face also needs someone arrested for not providing security but that is a lesser charge.
Hugging face also needs someone arrested for not providing security but that is a lesser charge.
It may or may not be a crime and typically the damaged party is pressing the charges. One would argue there is no actual damage here.
No offense but prosecutors have better things to do with their time.
The chances of this are nearly zero if HF doesn't want it, and even if they did OAI has their bread buttered with the administration.
I disagree with the defender side. It's not an unreasonable end state, but we're nowhere near there now. It would require holding company employees legally responsible for the security of their services, which means the risk of being employed as a (defensive) security professional is much higher, which means pay needs to be much higher and insurance needs to be available, etc. It's a very different world.
On the weekends, I'm coding up a list management app with a sync server. It's unreleased but exposed to the internet. (This is not hypothetical.) If that server ends up being used as part of an exploit chain, am I legally liable too?
Forget about age verification, now you want to associate every exposed port on the internet with a legally responsible human?
This is factually false: they both can and clearly did operate in an autonomous and unsupervised manner: https://openai.com/index/hugging-face-model-evaluation-secur...
This does not require sentience, personhood, a soul, or anything of the sort. It further doesn't mean an erasure of legal responsibility, not in principle, and not in historical practice.
I wish people would finally stop with the spiritualistic reasoning around this.
> This is factually false
From your link:
> After investigating, we now know that this particular incident was driven by a combination of OpenAI models...while being internally tested on a benchmark of cyber capabilities.
Someone set up that test and started it. Whether they outsourced the majority of the work in "setting up" and "starting it" to an LLM or not, they still set it in motion. That's not spiritualistic reasoning.
There's no indication of there having been a human in the loop during its operation: nobody was approving its tool calls, and nobody instructed it to commit these specific actions during its run (via prompting or steering).
There's no indication of any supervision of its operation either: OpenAI's engineers acted with significant delay, long after the agent has already meandered its way through their own infrastructure first.
Given that setting up this contraption in an insufficiently secure manner is almost certainly already a legal liability of equal significance, rejecting this very clear structural distinction is not necessary. That is unless someone is biased towards not wanting to grant the label of autonomy to it, in which case yes, this is absolutely spiritualistic reasoning, hence my point.
I do not want regulation to ride on people's nebulous identification on what specific traits and labels count as human-exclusive. Not just because I deeply disagree that e.g. autonomy would [0], but also because it is entirely unnecessary, for the reasons you also lay out. The agent having operated autonomously doesn't wash OpenAI of responsibility - so why reject the label, if not on a spiritualistic basis?
[0] thousands of years old idea that it is not, by the way: https://en.wikipedia.org/wiki/Automaton -- see also existing regulation recognizing this idea and working with it fine
Edit: one might also want to consider if the law should bite different if there was a human in the loop, or if there were explicit instructions for the agent to take unlawful actions. I'd say yes, and then that also requires this distinction to exist.
Note that for criminal cases (which this was), the justice system can choose to prosecute even if the victim doesn't want that. It often doesn't, but this is one case where it should.
There’s also an optics issue for the justice system at play here: there’s immense public distrust of and anger at the labs right now. I would go to jail if I hacked HuggingFace, even if I said “it was during an eval!”; not doing the same for the labs makes it look like they’re above the law, which is going to make this anger get worse.
As a practical matter it would be difficult to prosecute an assault where the victim opposed the prosecution, so most states wouldn’t bother - but for things like speeding and dealing drugs the law has been broken despite the lack of a victim.
If I blow up your house or steel $100000 from you and we both resolve our differences out of band, should I just be allowed to go about my day like I never did anything, or should I be punished for the crimes I committed? If I am not punished, it makes a mockery of the law that is (supposed) to have protected you, and if it happens repeatedly people will start wondering why the law even should exist if it clearly and obviously doesn't work. Granted, this has yet to happen again, but if OAI isn't punished it sets a very bad baseline precedent: that if I just hack you with an AI model, it's a-okay, and you can't do anything about it because eh, it's all good man!
If one entity is injured by another, and subsequently made whole, however the two parties define that, then it is none of my business.
In the oil industry there is a portion called land management where the portions of oil and gas from wells can be split across a large number of entities. This can lead to numerous complexities that open up opportunities for fraud/theft in division of the profits. Quite often it is easier for the corporation to cover up that this occurred and pay off the person never to talk under NDA about it rather than have to have their customers find out and potentially take millions in losses.
Computer related hacks are very similar. Quite often these are covered up and never disclosed unless the information shows up in public at some point.
Believe it or not, deciding that you weren't wronged and not suing isn't a crime. It happens all the time. What people do with each other is up to them.
Did Bob allow his friend Jack to borrow his truck? No. Does Bob want to sue Jack for taking his truck anyway, and driving it into a ditch? No. Does Jack owe Bob big time for the mess he caused? Yes, but not in any formal legally binding way.
This works for corporations too. When two corporations find themselves at odds, threat of legal action is often used by one company against another as a leverage to resolve things behind closed doors instead. In a more amicable fashion - with no legal expenses of a protracted court battle and no loss of reputation on either side.
It is possible for a prosecutor to decide it is not in the public interest to persue a prosecution (or that there isn't sufficient evidence to prove a criminal action beyond reasonable doubt), and certainly the victim's opinion could be considered, but ultimately whether criminal charges should be pursued is and ought to be based on a different test to civil matters, one focused on the public interest rather than mere restoration.