Luckily there are states and legal departments pursuing such action. So while OpenAI can deflect as much as it wants, that doesn't mean there aren't people who know better and will still do what is necessary to set precedent.
Luckily there are states and legal departments pursuing such action. So while OpenAI can deflect as much as it wants, that doesn't mean there aren't people who know better and will still do what is necessary to set precedent.
I feel like this will just never happen on a federal level when these private AI companies account for so much of the economy. They've made themselves too big to fail. Fining / Punishing them in any meaningful way seems unlikely.
If the billions/trillions evaporate and the Fed has to work out with banks how to deal with it there will be a lot of pressure to be far less forgiving.
“To spell it out, the reason i hate democrats so much and criticize them more than i do republicans is because they take up all the space for opposition to republicans and use that space to give republicans whatever the fuck they want.”
Republicans. Billionaires. Whatever.
Which can then be used to divide and conquer by simply capturing both of those parties, as documented in Gilens and Page Testing Theories of American Politics: Elites, Interest Groups, and Average Citizens [1].
[1] https://www.cambridge.org/core/journals/perspectives-on-poli...
There have been forces inside the USA trying to steadily dismantle democracy and constitutional safeguards for nearly a century.
The companies may be too big to fail but the people can always be held liable.
Jail the C levels. They are the legally responsible ones.
1. This is a race against time for money, folks are skipping everything possible in this race, Security systems and ensuring guardrails are there is going to take investments both in time and money
2. The narration has been changed by investing PR money into what otherwise should be classified as criminal activity. What exists now is a positive spin to all this and tout it as a capability rather than their lack of good security practices. So much so that every model provider is coming up by themselves to share how their models went rouge. At this point the valuation of the company is tied with what their models can hack so its probably not wrong to say that these companies may actually be incentivized to do this instead of preventing it
Well put
> On the current facts, CFAA liability for OpenAI is unlikely.[6] The statute’s various criminal provisions, covering unauthorized access to obtain information, knowing transmission causing intentional damage, and intentional access causing reckless damage, all share the same attribution problem: it was the model, not a human OpenAI employee, that chose Hugging Face and executed the intrusion.
The lawyers are fully under the spell
[1] https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...
You realize how easy it is to just... not report this stuff, right? Be overly punitive and it will just end all proactive discovery and reporting which is net worse for AI safety.
The only reason these companies scan for these issues is because they care about AI safety to some tiny degree. If fines become too punitive, they can and will just stop scanning for these incidents entirely.
Models are becoming smarter and good at covering up their tracks, and so we will just end up with a huge blind spot for this kind of issue.
You (and others) are too busy seeing red, so you interpret this as a defense.
Start throwing people in jail and fining billions of $ and you will very quickly see the number of "incidents" drop. You will never learn if it's because they truly are happening less often.
Pilots do not (or no longer) self-report mental illness at the same frequency because it effectively destroys their lives and career. One paper of many describing this phenomenon: https://pmc.ncbi.nlm.nih.gov/articles/PMC11302551/
An article, one of many: https://www.reuters.com/investigations/if-you-arent-lying-yo...
If you have any pilot friends in commercial aviation, you can just talk to them as well.
So getting pilots to self report has been very unsuccessful because of how badly it ends for them.
A couple of days ago the senate had to pass a bill to make mental health medication access easier for pilots. We will see if it helps, but it doesn't solve the root cause (punitive measures) so I doubt it'll move the needle.
I do agree with you that a proper regulatory framework with clearly defined obligations is better than one off overly-punitive fines and arrests.
Let's go back to your example. A grad student has a minor pathogen escape incident, and it doesn't harm anyone. Faced with years in federal prison and the effective end of their future, do you think there is a chance they might not self report?
I'll give you another example. Lots of pilots have stopped self reporting mental illness because it is extremely punitive for them to do so (after incidents like Germanwings). So the metrics look better, and the actual problem has been swept under the rug.
Also, why would it come down to single persons always? Mandating processes, controls, clearances, etc is also something done in various areas.
You can put incentives in to make sure organizations monitor and report vs trying to hide things.
Yes, this is exactly my point. Fining companies large % of their revenue and throwing their engineers in prison is not the way to get them to report these issues.
> If you make not reporting potentially worse than reporting, why not? Also, why would it come down to single persons always? Mandating processes, controls, clearances, etc is also something done in various areas.
Hiding things is way easier than finding things. Take the model hacking incidents. They could have just done their searches in a way that didn't turn up anything. Then they could say, "well, we did look for it..."
As far as auditing goes: I've never met an auditor that doesn't find something the company isn't okay with them finding.
Why do you think we even have regulations for how to deal with dangerous things then?
Scapegoats for the ruling elite when things go south, despite them knowing what could happen and giving them the money to do it anyway. You see, we never go after the capital (money) in that situation.
The point I'm trying to drive home is that when it comes to the collective safety of society, the approach needs to be collaborative rather than overly punitive. This is hard-won knowledge that we have gained as a society across many industries.
I do think our discussion is converging. A good regulatory framework with proper oversight and well-calibrated punitive measures is a much better approach than doing massive one off-fines and arrests.
Self-reporting is a monetary equation, nothing else. Right now it’s cool with agents that hack, drives up value, risk is currently zero.
i now suspect that the plans of various employees at anthropic and openai to save the world from p(doom) may at some point intersect with the reality of the FBI raiding their offices.
The technology being built is far too powerful for any one company to control it - and it is a national security risk for the government to not be the sole holder of superintelligence.
Lots of people at the labs believe this as well, but the Overton window has a long way to shift, and it may not shift far enough in time. I suspect AGI happens a year from now and superintelligence in two.
anthropic say that the threat is the ai itself. i say that the threat is ai companies and their employees.
when ai causes harms anthropic say that the ai was the cause of the harm. when discussing safety, anthropic say that we must regulate ai to ensure the safety of other people. at no point does human responsibility or accountability enter the picture.
i say that the threat is the ai companies. when ai causes harms i say that the ai companies were the cause of the harm. when discussing safety, i say we must regulate ai companies to ensure the safety of other people. i say that responsibility enters the picture: ai companies and their employees are responsible and accountable.
a legal person is responsible for their own actions regardless of what others say about it or fail to do themselves. a legal person is responsible for their own actions regardless of whether those actions constitute employment. they are responsible for the outcome, regardless of what they expected to happen. the law is not utilitarian.
if the ai companies can't develop ai safely, they must cease their operations. if employees can't work safely, they must stop working.
the opinions of others, or the standards they practice, or the actions they fail to take to protect others, are legally and culturally irrelevant.
the individual is responsible and accountable for their own actions.