Remix.run Logo
Iowa et al asks OpenAI to keep their bots sandboxed(iowaattorneygeneral.gov)
44 points by ArcHound an hour ago | 65 comments
hallway_monitor 44 minutes ago | parent | next [-]

SOLUTION: Make a law that someone is responsible for a bot's actions. Either the bot is signed cryptography with someone accepting responsibility, or responsibility falls to the CEO. Charge Altman with hacking hugging face. Throw him in jail where he belongs. That will realign safety incentives.

If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???

_verandaguy 32 minutes ago | parent | next [-]

I think this is a logical extension of the workplace rule of "you own what your bot writes;" it's hypocritical not to hold corporations to the same standards as individuals (I say, with terminal naiveness)

matheusmoreira 21 minutes ago | parent | next [-]

> you own what your bot writes

Kinda weird that this is everyone's attitude while the copyright lawyers are saying the opposite. Total liability without any actual ownership.

romanows 12 minutes ago | parent | next [-]

"own" in the sense of "be responsible for the consequences". Not in the sense of "be able to grant reproduction rights".

daveguy 11 minutes ago | parent | prev [-]

GP's phrasing was not precise, but I think most people understood it was liability ownership and not copyright. Ownership with respect to copyright and ownership with respect to legal liability are two completely different concepts.

_verandaguy 5 minutes ago | parent [-]

That's correct. What I meant was that if my bot writes defective code for whatever reason, I am responsible for that (though conversely, if I get more done because of the bot, anthropic gets the praise).

inigyou 18 minutes ago | parent | prev [-]

That's hypocritical if you believe fairness is intended, but if you believe protecting rich people and hurting poor people is intended then the contradiction is entirely consistent with that.

DannyBee 22 minutes ago | parent | prev | next [-]

Lawyer here: This part does not require a new law.

Even though agents are not agents in the principal/agent legal sense (because agents have to be human), for the purposes of criminality, it does not matter.

Agents do not act autonomously (and every court to ever consider it has agreed), and therefore they would simply be considered an instrumentality of the crime.

So that part does not need a new law.

The real blocker is often that a lot of the crimes you could charge here require specific intent. Because the agent is just an instrumentality, it does not have separate intent (and can't be part of a conspiracy), so it's the intent of hte person using the agent that would matter. Without whatever intent the crime requires, they haven't committed a crime.

There are not a lot of non-intent crimes in this area, and this is on purpose. Otherwise you could get charged with a crime for say, running nmap and having it accidentally shutdown something important or killed a person or whatever because someone hooked it up to a TCP port.

segmondy 15 minutes ago | parent [-]

"Without whatever intent the crime requires, they haven't committed a crime."

I'm not a lawyer, but I don't believe this. There is definitely negligence, these companies have often talked about the danger of AI. They have often written about how their AI is breaking out of sandboxes or trying to manipulate the person tuning it. They should have had stronger guards and monitoring in place.

bluGill a few seconds ago | parent | next [-]

The problem is the law is about details. If an accidental loophole says this isn't a crime it isn't a crime even if it obviously is an accidental loophole.

US constitution, Article I, Section 9, Clause 3: No Bill of Attainder or ex post facto Law shall be passed.

That is the constitution, this right was so important they didn't even wait for the bill of rights to add it! I'm sure other countries have similar rules.

It is obvious to me that a crime was committed. However if it is legally a crime, and if so what the crime is are things I don't know.

DannyBee 7 minutes ago | parent | prev [-]

I'm not sure why you don't believe it? It's literally true? I guess if you want to believe it, go study law? I'm not really sure what to say there.

Negligence is not a crime, it's civil liability.

Gross negligence (reckless disregard for human life) is often a crime, and often there are crimes related to it (reckless driving, etc). It also does not require intent to injure, so it could be committed by, say, an operator by operating an autonomous vehicle knowing it was unsafe and could harm people. So it usually requires knowledge but not specific intent. Again, crimes like this are state specific, and sometimes even municipality specific so it's tricky to give an exact result without pinning it to a state.

However, for example, all states where autonomous vehicles are operating have statutes explicitly defining civil and criminal liability right now, so it doesn't get into the more general legal question of AI.

The same thing is already starting to happen with AI agents in general, it's just not there yet.

colechristensen 36 minutes ago | parent | prev | next [-]

>WHY has no one been charged???

I doubt huggingface wants charges filed.

bluGill 22 minutes ago | parent | next [-]

A crime was committed, if there is enough evidence then the state is required to prosecute and the victim has not choice in this. The victim can say they don't care and that will often hold weight for the prosecution, but that is the government's choice not the victims.

The victim sometimes file a civil lawsuit against the criminal, that is their choice. That is not a criminal matter though and different rules apply.

The attack was only a couple weeks ago. Looks like the lawyers responsible are gathering evidence and preparing to file charges, but they need to figure out exactly what crimes were committed by who before they can do so, thus more investigation is needed.

colechristensen 14 minutes ago | parent [-]

The "victim" doesn't have the final choice but their position is heavily influential and prosecutors don't decide if a crime was committed, that only happens at the end of the judicial proceedings. Calm down.

__MatrixMan__ 24 minutes ago | parent | prev [-]

They would be criminal charges. It doesn't matter what huggingface wants.

TZubiri 34 minutes ago | parent | prev | next [-]

No law needed, that's the way it already is.

DannyBee 28 minutes ago | parent [-]

Lawyer here.

Not quite.

Agents in the principal/agent sense have to be human.

However, every court to have ever considered it have held the human/company driving the agent responsible under vicarious liability/negligence/etc principles.

The only real defense that folks have tried is to claim the agent acted "autonomously", which no court has bought so far.

ricardobayes 25 minutes ago | parent [-]

Who bears the responsibility in a hypotethical scenario when a self-driving rideshare vehicle, without a human driver, god-forbid, hits a pedestrian?

DannyBee 16 minutes ago | parent [-]

Some states have autonomous vehicle statutes and some don't.

Let's assume the case none of them do, since it sounds like you are asking about "what would happen in the case this isn't specifically answered by a statute".

In that case, the short answer is:

Criminal liability - you could only really charge crimes that don't require specific intent. Reckless driving is an example. You could charge the company since they are the operator and the car is simply an instrumentality. In the end though, there just isn't a lot of people here with legally culpable conduct.

Civil liability - the company pretty clearly because civil liability often does not require the same kind of intent crimes do.

This is, of course, why states where autonomous vehicles operate have autonomous vehicle statutes :)

As a general rule, criminal law mirrors what society overall wants to decide is culpable/not, and the lag time isn't as bad as most people often think. That doesn't mean nobody ever gets hurt or dead without someone being culpable, they do, and it often leads to an law with a name - megan's law, etc.

Criminal law is mostly reactive though, not proactive, and to be honest, proactive attempts don't have a high hit rate.

jstanley 41 minutes ago | parent | prev | next [-]

Because nobody did it on purpose?

ArcHound 39 minutes ago | parent | next [-]

Someone should still be accountable, the same way you're responsible and accountable for what your dog or car does.

solenoid0937 38 minutes ago | parent [-]

If we are going to start punishing companies for security negligence, there are WAY worse cases than these models breaking out that have nothing to do with AI. This is bikeshedding at its best.

Also people would just stop disclosing bad things. You already see this in the airline industry where pilots don't report mental illness because of the retributive nature of the punishment.

kdheiwns 31 minutes ago | parent | next [-]

"But another company did some different bad thing" is the excuse employees of bad companies all go to immediately. Just because another person did something bad and hasn't been adequately punished doesn't mean you should get a pass. If one person gets away with going 50 MPH over the speed limit, it doesn't mean every person should be allowed to do it. Everyone should be punished, but there are always instances of some cases falling through the cracks. It doesn't mean the crack should be widened so all cases fall through.

solenoid0937 28 minutes ago | parent [-]

It's more like there are many people going at 120 MPH in a 50 MPH zone, that have ran over real people, but you punish the guy that self-reported doing 60 MPH because he drives a shiny, interesting Lamborghini and not a Prius like the others.

Anyone outraged about these AI incidents is not thinking rationally if they were not much more outraged about everyday companies leaking millions of people's PII, SSNs, which has done actual lasting damage and has been used by actually malicious actors.

People are just directing their anger at AI companies through this pretext. We all know open source models will democratize this ability anyways, so strap in for the ride.

kdheiwns 17 minutes ago | parent [-]

Turning oneself in doesn't absolve one of a crime. Never did and never will. Shouldn't, either.

And companies always try to pretend someone out there is worse and garner fake sympathy. OpenAI blew up the memory market and made tech inaccessible. The downstream effects of that are immeasurably massive and will have real consequences. It could even result in medical devices becoming too expensive for people. I don't care about my SSN being leaked. You can find it just by knowing where I'm born and every job I've applied to knows it already. But inability to afford technology affects everyone around me. The SSN red herring thing is not an organic argument.

solenoid0937 10 minutes ago | parent [-]

> OpenAI blew up the memory market and made tech inaccessible

This is not a "crime", has nothing to do with this incident, and simply confirms what I am saying about people using these events as an outlet for their anger at AI companies, as opposed to any rational reasoning about industrywide security negligence.

I could almost respect a viewpoint that says "we should punish companies for security negligence, starting with the negligence that has caused the most egregious harms." That is an internally consistent and rational viewpoint.

I cannot respect a viewpoint that's "I don't like the AI companies, so let me use this hammer I found on them specifically." It's purely emotional.

reddozen 19 minutes ago | parent | prev | next [-]

> there are WAY worse cases than these models breaking out that have nothing to do with AI.

And? Welcome to the big boy world. This isn't playground rules where you can complain "But Bobby was doing bad things too why isn't he in trouble?"

But you know this already. You're just pretending not to. Why?

solenoid0937 11 minutes ago | parent [-]

Addressed in my other replies

ArcHound 36 minutes ago | parent | prev [-]

Please tell me about such cases, genuinely interested.

I still think we should take the opportunity to discuss this case in particular.

solenoid0937 33 minutes ago | parent [-]

There have been data breaches where the SSNs and PII of millions of people have been exposed. That is far more harmful in real terms than any of the OpenAI/Anthropic mess.

reddozen 16 minutes ago | parent | next [-]

So OP asked you for one example and you can't give one? You just fall back to the generic statement slop, you must be a bot right?

Again, what's ONE (1) real world example of "SSN/PII" being illegally exposed that wasn't investigated or prosecuted.

ilogik 25 minutes ago | parent | prev [-]

An in the EU at least there are laws that fine companies that don't take security seriously.

solenoid0937 19 minutes ago | parent [-]

Even the EU bikesheds and focuses on shiny targets to land political wins with their constituents.

bix6 33 minutes ago | parent | prev | next [-]

Nobody stole from humanity, constantly told us how dangerous the invention was, and then set up systems that they couldn’t properly control to rush ahead of their competitors? Nobody did that on purpose? I think they did.

AbsurdCensor 12 minutes ago | parent [-]

You could say that same exact thing for the entire Industrial Revolution, but that doesn't mean we are going to destroy the looms even though some tried unsuccessfully.

skinfaxi 35 minutes ago | parent | prev | next [-]

If I let my dog off leash and it bites you and causes grave injury, no harm done then?

sebzim4500 25 minutes ago | parent [-]

In this case though no damages were done. It's more like you let your dog off the leash and it scared me a bit.

inigyou 17 minutes ago | parent [-]

Sounds like the crime of assault.

sscaryterry 25 minutes ago | parent | prev | next [-]

Ignorance is not a defence in law.

xgulfie 7 minutes ago | parent [-]

It is, sometimes. Trespassing for example. A lot of laws say "willingly" or "with the intent to"

trillic 24 minutes ago | parent | prev | next [-]

Correct, no mens rea, unless we're talking the internal reasoning trace of the model.

bluGill 17 minutes ago | parent [-]

Mens Rea is not required. Mens Rea makes a big difference in sentencing. (first degree murder: you planed the murder, homicide you had not intent of murder but things got out of hand in the moment):

exe34 39 minutes ago | parent | prev | next [-]

A lot of laws are involved in punishing negligence. "I didn't dump the dangerous chemicals in the river on purpose" isn't usually accepted as a defence when you choose to use the wrong truck and skipped safety protocols to save cost or rush to market for profit.

ModernMech 34 minutes ago | parent | prev [-]

That's why its so concerning.

dominotw 22 minutes ago | parent | prev | next [-]

then usa will become like europe that cant innovate out of regulations bag. saftety is meaningless if you have no food eat.

nautilus12 41 minutes ago | parent | prev [-]

Can they try to prove that he directed someone to direct the agent to do that?

datakan an hour ago | parent | prev | next [-]

"Attorney General Brenna Bird announced today she is leading a coalition of 15 states demanding transparency and accountability from the AI company OpenAI, led by Sam Altman, for its complete lack of oversight and transparency in the hacking of Hugging Face, another AI company."

Title should be edited. Its Iowa leading a coalition of many other states, not just Iowa on its own.

jwally 43 minutes ago | parent | prev | next [-]

Prediction: AI ends humanity not via some super cool/scary/robopocalypse - but as a marketing stunt gone wrong when a Frontier LLM accidentally knocks out water/electric/gas by hacking in and trying to patch them.

Phillip K. Dick meets Idiocracy.

utopiah 19 minutes ago | parent | next [-]

I remember (sorry can't give a proper quote) a biologist interviews about the fear of lab grown "super" seeds escaping the lab. They chuckled basically saying that nature is a very VERY challenging place. There are plenty of ecological niches but they are well guarded by incumbents.

Sure some new hacks will take place, including on poorly guarded infrastructure and yes it will have some very unfortunate consequences... but also infrastructure is precisely designed to be resilient. There is quite a bit of failsafe, redundancy, etc built in which is precisely why those projects are typically slow and expensive, unlike a random website for a restaurant.

TL;DR: nope, some isolated incidents will happen but without chain reactions.

bix6 31 minutes ago | parent | prev [-]

OpenAI and Anthropic vs Brawndo Corporation. The final showdown.

jazzyjackson 29 minutes ago | parent | prev | next [-]

Robots should be regarded as extensions of their operator wrt liability. It is illegal to access a computer outside of authorized use already, someone lets a bot make its own plan without watching, hold them accountable

skinfaxi 33 minutes ago | parent | prev | next [-]

If Waymo can be liable for their cars, why isn't OpenAI liable for its AI?

skybrian 19 minutes ago | parent [-]

Who says they aren’t?

mrbluecoat 44 minutes ago | parent | prev | next [-]

Glad the statement was published but sadly nothing will come of it other than a brief formal statement from OpenAI acknowledging safety protocols were lacking, apologizing for the incident, and promises that new safeguards are now in place that will prevent such event from occurring in the future. The threat of semi-autonomous AI threat actors will never go away until the financial incentive that buoys unchecked growth at all costs goes away.

bluGill 9 minutes ago | parent [-]

Set yourself an alarm for 5 years from now to review. Investigations take time. Often by the time charges are made everybody has forgotten about the incident. It only takes a few times where things go away without charges to leave an incorrect impression that nothing ever happens.

sam_lowry_ 43 minutes ago | parent | prev | next [-]

Iowa asks? Why don't they just open a criminal investigation related to the hacking of HuggingFace?

cestith 26 minutes ago | parent | next [-]

It’s actually Iowa leading a coalition of 15 other states making demands. It’s not a prosecution yet, but they demand the preservation of evidence. They’ve promised to protect whistleblowers. They are saying there may be criminal or civil liability involved. They gave them a cease and desist on similar testing until they can show they can do it safely.

The Iowa-led coalition is joined by the attorneys general of Alabama, Alaska, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah.

The letter’s last paragraph reads:

    OpenAI has an obligation to act responsibly and to follow State and
    federal laws that protect Americans’ safety and security. When OpenAI takes
   actions that imperil the welfare of our citizens, State Attorneys General will
    step in to protect them. We intend to take all steps necessary to protect our
    States and all Americans from the unprecedented risks posed by OpenAI’s
    irresponsible products and conduct.
bluGill 11 minutes ago | parent | prev | next [-]

They are opening that. This is the first step: figure out what crimes were committed by who. As I said a couple weeks ago when this broke, it looks like a crime was committed and I hope someone is charged. However we can't just charge everybody who works for openAI with the crime of speeding (even though it is probably true) - that is both the wrong crime, and also is highly unlikely everybody at openAI was involved.

cautiouscat 31 minutes ago | parent | prev | next [-]

I’m not a lawyer. However it probably comes down to jurisdiction.

iAMkenough 38 minutes ago | parent | prev [-]

Brenna Bird cares more about publicity than action.

alansaber 35 minutes ago | parent | prev | next [-]

We probably want to discourage frontier labs from security testing in prod

skinfaxi 32 minutes ago | parent [-]

I don't mind if they point it inwards.

drsopp 32 minutes ago | parent | prev | next [-]

The relevant word here is airgapping, not sandboxing.

lorreyfum 17 minutes ago | parent | prev [-]

Can we please enforce existing laws? Maybe AI and robotics, and get rid of all the lawyers.

bluGill 15 minutes ago | parent [-]

The job of lawyers is to enforce the existing laws. (well they are a part of the enforcement, there are lots of other parts)