Remix.run Logo
john_strinlai 4 hours ago

>Felony Bench counts unique instances where AI agents inadvertently compromise or affect third-party entities.

a bit silly, as one typically has to prove intent (which is why security researchers don't get slapped with felonies all the time).

"inadvertently" and the existence of guardrails/sandboxes/etc make it pretty unconvincing that these incidents were intentionally malicious.

still a fun thing to track, but the name is just a bit overstated.

chrismorgan 2 hours ago | parent | next [-]

Under the law of Moses, if your bull gored someone, you were not responsible; but if it was known to be a gorer, you were responsible if you didn’t ensure it couldn’t gore someone.

I don’t know exact parallels in current law, but I presume there will be things like that.

The OpenAI/Hugging Face case sounded rather like OpenAI building a fence around their bull that was known to be a gorer, and then thumbing their nose at it and saying “nyaa! bet you can’t break the fence!” and walking away while listening to loud music.

In Australia, if you have a fire and leave it unattended and it escapes, it’s your fault, you were supposed to keep watching as long as it was burning.

stickfigure 9 minutes ago | parent [-]

Nobody got gored. HuggingFace may have the right to make demands; presumably they have already worked that out with OpenAI privately. Not really our business.

lokar 4 hours ago | parent | prev | next [-]

Can’t gross negligence or indifference to consequences lead to a felony?

wbl 2 hours ago | parent | next [-]

Mens rea requirements are per crime and can vary wildly. Its difference between murder and manslaughter. The CFAA requires knowingly which is tough to prove.

john_strinlai 4 hours ago | parent | prev | next [-]

i dont think any of these cases meet the bar of gross negligence, which is a pretty high bar. it requires proving a "conscious and reckless disregard".

which, again, sandboxes and guardrails and such would make a gross negligence argument unconvincing.

Grombobulous 3 hours ago | parent | next [-]

I think that if Hugging Face had filed a police report that OpenAI could have been charged with a crime.

I’m partially surprised that they didn’t do exactly that. If I ran a corporation I would assume any intrusion attempt by another company was intentional. Why wouldn’t I? Corporate espionage is super common.

I assume the answer is that these executives know each other personally.

sebzim4500 43 minutes ago | parent | next [-]

What possible upside exists for Hugging Face to go after one of their most important partners in that way?

john_strinlai 3 hours ago | parent | prev [-]

charged is possible, however i doubt there would be a conviction for the reasons i stated (no intent).

Grombobulous 2 hours ago | parent [-]

I think it’s most likely you’re right, but I’m the weirdo who thinks there’s actually a non-zero probability that there was negative intent and that the “accidental” aspect is a form of damage control.

If someone broke into my house but then claimed they didn’t mean to when they saw I was home, I’m not sure I’d take them at their word.

lokar 3 hours ago | parent | prev [-]

How many escapes until it becomes reckless disregard?

john_strinlai 3 hours ago | parent [-]

it's not about the the number of escapes, it's about whether reasonable and conscious effort is being expended to prevent the escapes.

there could be 1,000 escapes, where each one was enabled by novel and unexpected chain of 0-day exploits. not likely to be considered reckless disregard in court.

there could be 1 escape, where there was no sandbox, no guardrails, no instructions to avoid damage, etc. which would likely to be considered reckless disregard (well, more likely to be, but still, reckless disregard is a high bar).

lokar 2 hours ago | parent | next [-]

Are you sure? At some point a reasonable person would conclude that this activity can’t be conducted safely.

john_strinlai an hour ago | parent [-]

what i am getting at is that it is impossible to answer the question "How many escapes until it becomes reckless disregard?"

reckless disregard is a specific legal term, with specific criteria, and none of the criteria cares about "number of attempts" (or number of escapes, etc.).

fwip 2 hours ago | parent | prev [-]

Surely after 999 escapes, a reasonable person could conclude that the sandbox is not a sufficient precaution?

john_strinlai 2 hours ago | parent [-]

it’s not a perfect hypothetical, but it illustrates the point that the number of escapes is not the deciding factor of what constitutes reckless disregard.

GPerson 4 hours ago | parent | prev | next [-]

AI corps rely on willful distortions of intent in laws to get away with moral crimes all the time.

Edit: changed labs to corps because it’s time to stop pretending these are places of science.

3 hours ago | parent | prev [-]
[deleted]
sanid an hour ago | parent | prev | next [-]

What judicial system are you talking about? The fist incident in the list is something that happened in Australia. This is a technology used worldwide so I don't see how applying US standards works out here. Especially when there are countries out there that don't require intent and will look at the negligence presented.

john_strinlai an hour ago | parent [-]

>This is a technology used worldwide so I don't see how applying US standards works out here.

all three companies mentioned are headquartered in the usa, and im familiar with the CFAA in the us, so i am applying those standards. i should have noted that, sorry.

>will look at the negligence presented.

as far as i am aware, no evidence of criminal negligence has been brought to the public. has australia brought a case against openai or accused openai of acting negligently?

layer8 an hour ago | parent | prev | next [-]

In the US, a felony by definition is any offense punishable by more than one year of prison (or by death) [0]. You could still call it silly on the grounds that AI agents aren’t put into prison as a punishment (though death might be considered an option).

[0] https://www.justice.gov/usao-ndil/programs/vwa-felony

Groxx an hour ago | parent | prev | next [-]

Roughly none of these fall under normal security researcher behaviors.

john_strinlai an hour ago | parent [-]

the mention of security researchers was to illustrate that intent is a crucial factor of CFAA cases.

miltonlost 2 hours ago | parent | prev | next [-]

"Doing crimes, but a robot didn't mean to and you don't know its intent" is understating the evil acts. Soon a robot can commit a murder but nothing will be done because of your line of reasoning.

TaLiTr 42 minutes ago | parent | next [-]

> Soon a robot can commit a murder but nothing will be done because of your line of reasoning.

That's rather hyperbolic.

Are you seriously suggesting in that situation the robot should be accused of murder? The robot's operator could be accused of murder, but it could just be negligence without intent. Because that does, and should matter to the law.

john_strinlai 2 hours ago | parent | prev [-]

it's not my line of reasoning, i didn't invent it. it's how the law currently works. intent is the crucial factor in CFAA cases.

maybe that changes down the road as a result of llm's and increasing frequency of similar cases. that has not happened yet.

altmanaltman 3 hours ago | parent | prev | next [-]

its a meme not a metric

elwell 3 hours ago | parent [-]

So is the comment you replied to.

LordDragonfang 3 hours ago | parent | prev [-]

"Inadvertent" from the perspective of the humans directing them. The intent behind the felony comes from the LLM agent itself. (No, I'm not interested in arguing with someone for the umpteenth time that LLMs can't have intent or agency)

john_strinlai 3 hours ago | parent | next [-]

with how the law is written today, software cannot be charged with a crime, so the only intent that matters in the criminal sense is the humans directing the llm.

jdiff 2 hours ago | parent | prev | next [-]

You may not be interested in arguing but there are several blatant issues with the statement. If you're not charging the humans driving the software, who are you charging? The weights? The weights + the specific context window that produced the behavior?

not_wyoming an hour ago | parent [-]

I don't think this is a difficult question. The US has a history of civil product liability cases - see tobacco companies (Philip Morris), the Ford Pinto, the recent Meta cases, and the cases against character.ai.

From Investopedia [1], "[f]or a product liability claim to succeed, the plaintiffs in the suit must prove that a product was defective at the time it was transferred from the accused, and that the defect did cause the injury that's been claimed". It doesn't seem like a huge leap to me to argue that these models were defective insofar as they could not be safely used in a way that did not break the law.

I'm not a lawyer, and I'm not arguing that this is legally cut-and-dry, but I do expect that we'll have some answers about whether AI companies bear any sort of product liability sooner than later.

1 - https://www.investopedia.com/the-5-largest-u-s-product-liabi...

IAmBroom 2 hours ago | parent | prev [-]

> No, I'm not interested in arguing with someone for the umpteenth time

... why my claim makes no rational sense.