| ▲ | Who should be held accountable when an AI Agent (accidentally) acts maliciously?(blog.greenpants.net) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 29 points by Greenpants an hour ago | 52 comments | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | CatDaaaady 32 minutes ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I don't see how this is such an unclear legal question. If I fire a computer program that mistakenly causes another person harm, its my fault. Or it would be the maker of the program's fault. I feel we have established pattern for this already. Until we can agree whether AI is conscious, which we never will, AI and AI agents are just property working on behalf of humans. I could see a future where AI companies/services indemnify consumers who use their agents but _not_ indemnify corporations that use their services. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bunderbunder 3 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I’m pretty sure that this is a solved problem. For “classical” machine learning, it worked like this in my neck of the woods: The model’s operator is directly liable for any undue harm caused in the course of the model’s operation. This includes models acquired from third-party vendors. The operator is responsible for ascertaining the model’s fitness for purpose prior to deployment, and for ongoing monitoring of its operation. If the model came from a vendor, and the operator conducted due diligence but it turns out that the vendor materially misrepresented the model’s capabilities in a way that contributed to the harm, then the vendor can also be held liable. If that happens then it’s up to a court to apportion the liability. IANAL but I see I reason why these established principles shouldn’t apply to GenAI. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | walrus01 an hour ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I wonder if there's any legal precedent for other "not fully human intelligence" property that escapes containment and causes damage to a third party without any active malice, but nonetheless damage was caused. For example: A. You own a large amount of cattle on a ranch. B. Cattle are property. They're not human level of sentience, but people agree that cattle are capable of autonomous actions and going places and doing things based on their own instincts and nature. C. Your cattle bust out of a fence on your ranch and damage something belonging to your neighbor. Let's say for the sake of an example of something cattle are known to do, they go spend a whole day rubbing up against your neighbor's car and severely scratch it and mess up the paint job on it. D. You didn't instruct or train the cattle to cause damage, and the cattle have no actively malicious intent of their own, but nonetheless damage was caused. Further theoretical: Your cattle wander into a major highway and cause a car wreck, the local sheriff's department is called out as part of the chaos and has to shoot some of them to put down the wounded beasts. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | blacksqr 2 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Obviously the most proximate human being in the decision-making chain that led to the AI agent being deployed. The nearest person with the power to say no who said yes. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | beloch 11 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
A major problem with LLM's is that they don't reason in a way humans are used to thinking of reason. If we tried to give them something like Asimov's laws of robotics, they likely wouldn't be able to apply them reliably. This is a challenge for AI companies working on the bleeding edge, and it's fairly obvious those companies should be held accountable for mistakes, whether caused by carelessness or not. It's no different than an oil spill. They may or may not be subject to charges based on what happened but, regardless, they are responsible for cleanup costs. What's less obvious is who should be held accountable when a customer of one of these corporations uses their product and it unexpectedly does bad things. e.g. A fellow asks his AI assistant to book him into a high-demand class at the local gym, so the LLM probes the gym's website for vulnerabilities, books him into a date that is farther into the future than the system is supposed to permit, and then drops other people from earlier classes until he's bumped into the one he wanted. If the gym decides to press charges, who should they be applied to? This sort of case is more difficult to answer. The company that provided the AI certainly bears some responsibility. Perhaps most of it. Possibly even all of it if they represented their AI as reliably law abiding. If a user knowingly uses an AI that is not guaranteed to abide by the law, is that user partially liable for what the AI does too? IANAL. I'd love to hear perspectives on this question. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | throwitaway222 11 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
We had the same debate when self driving cars started to be a thing, and we decided that the companies making the self-driving tech are responsible.. So if an AI agent is asked to build a giant base for someone in MineCraft, and decided to build a swarm of additional agents, and one of those agents says "Time to destroy all humans" and autonomously hacks into the pentagon and fires the nukes - the company that developed the model is responsible. That being said - if the nukes deploy successfully, I have two questions: 1. If no one finds out, is anyone responsible? 2. Was any of this actually real? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ngetchell 39 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Both the operator of the AI agent and whomever released it. I'm sure the user agreement that companies agree to would shift the blame onto the operator but I feel that both should be held accountable. This really is just a tool and courts should treat it as such. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | newobj 36 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
An ordered list of officers of the company who go to jail depending on how many years must be served as determined by sentencing. Assume something like 10 years per person. If it's 300 years of sentencing, then 30 people. If the sentence exceeds the list of people, the company is nationalized. (And everybody goes to jail.) | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | mikrl 9 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
At the core, how are these agents any different from what Aaron Swartz was driven to suicide for? In both cases, someone ran some software that maybe called other software that ended up doing an action which was possibly illegal. Downloading journal articles is worthy of punishment but compromising multiple websites is worthy of… heady press coverage? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bilekas 14 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
"Who's responsible for training an assassin and asking it to go out into the world ?" The fact this is being discussed as a legitimate question is the real story. "We trained this beast of processing power, we asked it for a task, and it did something wrong... Who's to blame ?" Trained on stolen books and material, every word we've all spoken, most lines of code we've ever written with not even an acknowledgment. Must be the data scientists in their rooms calculating the response rate of every token to blame ? Our version of AI is not sentient. Stop making it seem so. But we need to ask where to look for the culprit ? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | autoexec 28 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
If a person's use of AI would cause a reasonable person to expect harm to result, the person should be accountable. Otherwise, if AI causes harm and it was used in a way that a reasonable person would not expect to result in harm, the AI company should be held accountable. Just because a person should be accountable doesn't mean that the AI company can't also be if their service should never have allowed something to happen in the first place, but we're probably going to want actual regulations around what sort of guardrails they're expected to have. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | crorella 8 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Should be both the entity providing the platform where the inference is running + the entity giving the prompts/instructions. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bob1029 28 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I don't see this as being much different from a crane operator or airline pilot. One of my clients has enforced a policy where a live human user principal must be supplied as a header with any requests outbound from the AI system. The effective policy is that you are completely (100%) responsible for what your agent does on your behalf. The AI system is designed to request confirmation for any potentially destructive actions. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | tptacek 10 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Obviously, the labs (or any other operator of a model) should be accountable for malicious or destructive actions taken by agents. And they are. I don't think there's any controversy about the civil liability exposure frontier labs have if their agents cause damages, and it is remarkably easy to rack up damages by causing computer intrusions even if those intrusions don't cause obvious direct damages; for instance, many organizations are required to engage forensics firms at nosebleed-high costs to assess the impact of breakins in order to retain insurance coverage. The "controversy", if you want to call it that, is over criminal liability. People feel that frontier labs should be at least as responsible criminally as human hackers are when they're caught (to be clear: an extraordinarily rare outcome). The problem is: they're not criminally liable, not so long as the frontier labs operate without specific intent to cause breakins. Mens rea thresholds are their own whole area of criminal law, and there are stark differences between "recklessness" and "intent". All of the meaningful criminal CFAA predicates require actual intent: someone, a human being, has to deliberately set out to create the outcome where a specific intrusion happens. They have to want it to happen and act accordingly. In the most severe cases, they also have to do so with intent to defraud. We could change the law to make it easier to prosecute breakins without provable intent, but I don't think that would make HN people happier. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | jumploops 13 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
In the end, the only job left was liability. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | Boxxed 39 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
This is a whole lot more obvious once you stop anthropomorphizing LLMs. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | Eddy_Viscosity2 25 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Its been well established that blame is distributed in an inverse proportion to the various parties wealth/power/status metrics. The higher these metrics, the lower the accountability. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | phoghed 24 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Nobody cares. Seriously, beyond navel gazing on social media, nobody cares. By the time it’s an actual problem and not just these guys trying to use it for viral marketing, you’re going to have many thousands of people doing it maliciously with intent to worry about. You’re going to be flooded with Russian hackers with no recourse. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | jdkee 42 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
“A computer can never be held accountable, therefore a computer must never make a management decision.” – IBM Training Manual, 1979 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | mahboi 28 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
"Back in 2022, a Google employee already thought their AI model was sentient." Sigh, this meme again | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ofjcihen 31 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
At the moment, with LLMs the way they are, I’d say the operator. If we reach some kind of future where LLMs are integrated into public works in some major way… I would say that could open up the possibility of the creators being held accountable (Not saying this will happen or would be good at all). | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | jamesgill 39 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Now, imagine AI helping to operate your self-driving car. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | CurbStomper2 44 minutes ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Mostly Scam Altman. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||