> They took actions that would be considered as crimes if a human took them
He is so close to the solution but spends the entire article discussing technical solutions where a political, social and legal solution would be much more effective.
> They took actions that would be considered as crimes if a human took them
He is so close to the solution but spends the entire article discussing technical solutions where a political, social and legal solution would be much more effective.
If this is done systematically (i.e. in jurisdictions across the world) I believe the problems will be solved in short order; we won't have to mandate what sort of training is "allowed" or not, "safe" or not. The creators and users will sort these themselves, as their incentives will be properly aligned (i.e. they are liable for what the agent does). I am confident that this approach would see a great blooming of very trustworthy AI models.
Still, I have no idea why OpenAI & co. are not being sued for these hacks.
So, your question is spot on- I think the speed will be an issue. On resilience, I am more optimistic.
The old quote, "The wheels of justice turn slowly, but they grind very fine" (as well as I can remember it) seems to apply. I expect lawsuits to start landing in the coming years.
They were held responsible for basically misleading people, and that's 'complicated'.
If OpenAI 'software' goes out and does something, it's OpenAI's fault.
If Walmart revs up a truck, points it downtown, and 'lets the truck go' ... that is Walmart's fault.
There's nothing complicated about liability, no need to see their internal emails, no need to gather 'intent'.
This not like Instagram 'social harms' either, which is more like Tobacco.
We don't need complicated thinking - agents are not externalized for their controllers.
'It's just software'.
The fact we're even having discussions about it just crazy frankly.
OpenAI broke into HuggingFace, that's it.
HF can sue them, or not, or whatever.
We already have the laws. It is just software. But somehow people are confused that it is not.
That's just jargon.
It's just software
We have all the laws we need.
If some company ended up doing some horrible thing, we would not say 'companies software exposed 1 Million identities'.
We would say 'ABC Corp. exposed 1 Million entities'.
There is no 'agent'.
ABC Corp 'did it' ... or the individual in the org 'did it'.
The 'gun' did not 'shoot' the other man; we say 'a man shot another man'.
That's it.
And yes, Dr. Bengio is bit odd with all of this.
At least we have laws for what OpenAI 'does' to others, in whatever form.
If your dog kills someone, you are accused of murder.
[at least, in the jurisdiction where I live]
If your dog gets this treatment, why not your AI?
There was a sow in Falaise in northern France that killed a kid in 1386. The town dressed the pig in a bonnet and hanged it after sentencing the pig itself and not its owner
But… maybe that’s just medieval nonsense
Was the owner negligent in controlling their pig/dog/AI?
Was anyone else negligent along the way?
For example if the pig was just a normal pig, the owner cared for them normally, and there was a freak accident where the pig escaped and happened to kill a kid? Obviously nobody at fault.
If you have a dog with a history of violence and let it walk around off-leash with you around town, and it kills a kid? Absolutely the dog owner was negligent and should be charged.
Did you buy an AI sold to you as secure and the provider implies that it’s in a sandbox? Provider is on the hook for the damage.
Copyright immunity was one thing, annoying yes but naturally a civil matter, this shit is a different level
Secondly you'd have to convince a jury either that OAI intended to hack the targets, or that they were criminally negligent. Intent would obviously not be provable since they likely didn't, in reality, intend for it to happen. Regarding negligence, OAI's attorney would argue that the agent was in a sandbox, that industry-standard security protocols were followed, etc. It would not be anywhere near as much of a slam dunk case as you're imagining. It would be similar, for example, to an assault case where someone's dog broke off of a standard leash and attacked someone.
And tort law only works when the plaintiff believes it is in their overall interest to sue. If a corporation decides it isn't in their strategic interest to sue a partner corporation, nobody can make them. And even if they do sue, the amount necessary to settle a small cybersecurity incident is likely well within the budget of a megavendor.
And the 2 other incidents with OAI/ANT had the same issue, but it's even funnier - sandbox in those cases had a direct access to internet because someone forgot to configure it right.
I've seen very early models do similar things on my machine when they hit some unexpected blocker when trying to access a path. I remember early sonnet opening a file in browser because OS sandbox prevented from accessing it directly.
I've also had models discover a syslog-ng server (that I for some reason had ssh key inside), to get into my unraid server because machine they were running on didn't have direct network connection to Unraid server.
It can't be just me who is aware LLMs have been doing such things for the better part of last 2 years. I probably have better sandboxing on my machines now than trillion dollar companies crying AI will kill us all. That's at the very least, negligence to me.
I do get your point, I just think an overly strict definition can be awkward too. This wasn't as simple as the sandboxes having internet access and writing "pls no internet calls" in the prompt.
Who now owns HF? Nvidia
Who supplies hardware to OpenAI? Nvidia
Who is now not pressing charges? …
This incident is a long way under the carpet.
I assume OAI published those details after checking with their legal department. So there’s a good chance that there isn’t a chance for prosecution.
Plus they probably published that after knowing that the nvidia/HF deal was happening.
So instead this “security incident” should have been spun as OAI is honestly admitting its faults and AI is dangerous and therefore open weight models (hosted ironically by HF) should be banned. That spin didn’t really happen …
But this isn’t just civil, it’s criminal. Hacking is a criminal offense. This could be a CFAA violation. That’s landed people life in prison before. There, you don’t need the victims to be motivated. The federal prosecutors could just go ahead.
HF doesn't want to lay charges against OpenAI and it's totally reasonable.
Now - they absolutely should have that right, and I think they do.
The issues are
1) OAI it seems was not trying to cause them harm, there wasn't a ton of harm, they are both groups trying to advance AI. One experimenter's lab screwed up next to the other. It's not evil, just irresponsible.
2) HF was fine with the publicity. HF got at least $50M in free attention out of that. It put them on the front pages of news around the world. It put them at the 'centre of the AI drama' and cemented their role among the 'Tech Elite Brands'.
And probably some other things.
This is one Desperate Housewife or Jersey Shore character 'spilling a drink' on the other. It's probably not intentional, and the ensuing drama is good for both of them.
For the last 20 odd years this excuse-o-rama that covers anything from data leaks to broken software to dystopian social media has been the wind in the sails of big tech.
“It’s software therefore we’re not responsible” attitude is wearing thin on many innocent bystanders and I think thats also a justified stance.
And it’s not like they didn’t know this could happen, Nick Bostrom talked about exactly these containment failures in his “Superintelligence” book of 2014. So to throw up their hands and say “oh we can’t have known of the dangers” is also sadly untrue.
You are correct that these organizations should be held accountable in proportion to what occurred. In complete agreement here. But let’s say that’s done. There’s still an enormously complex and interesting technical challenge left over. Let’s collectively talk about that part.
So the gov reprimands OAI heavily, maybe puts them out of business even, fine. But does that meaningfully decrease the likelihood of an enemy breaching our networks intentionally (or unintentionally) with these tools, or triggering some cascading disaster of locking up major infra and networks due to uncontainable swarm behavior?
It seems like the idea of arresting our way to a drug free society. Yeah, we have the laws, but it might not actually work towards the ultimate goal.
You know, a proportional response. As opposed to closing a massive business over a couple of engineers screwing up.
How about we don't, seeing as how that's the root of the actual problem that we're facing today in September of 2026?
You can either litigate each case, or you can just automate, which is what regulation is.
> Risk management is not just about cybersecurity, corporate responsibility or regulation, although those matter too.
What you're getting at is more about who to hold accountable and how to do it. While that may be important, its only an after the action response and won't stop future hacks or similar from happening.
If the US gov't passed laws and enforced them strongly, this problem could be solved the same way the gov't solves it: air-gapping the networks on which they do this work.
> He is so close to the solution but spends the entire article discussing technical solutions where a political, social and legal solution would be much more effective.
There are exceptions in laws for crimes committed by entities depending on cognitive capabilities. No sane, humanistic legal system sentences children and mentally disabled and mentally ill people to stringent punishments of the same degree as functioning adults, and certainly do not punish their caregivers for their wards' actions. There are of course exceptions to that as well, depending on the degree of negligence involved. And then there's the whole corporate entity system intended to shield individuals from consequences, in the pursuit of a social good.
How does one account for all that when considering an evolving artificial intelligence landscape.
There is no question that ai in some form is a social good; anyone claiming otherwise is dissembling, to others or themselves.
Regardless, society is not ready for this tech, just as it was not ready for the consequences of prior tech such as corporations, gunpowder, mass manufacturing, railroads, electricity, automobiles, flight, wmd, computers, internet, social media, crypto.
Many of these required new ways of thinking and considering consequences when things went sideways, and what was needed wasn't clear until the ramifications & consequences became deadly clear.
See you on the other side. Maybe.
that's the headline. When you connect to random number generator to the "Do Things" button you are the one who is responsible. IF you don't like that responsibility then don't connect the generator to the button.