Remix.run Logo
▲ bluegatty 3 hours ago

"OpenAI models attack websites and take anything they can out of them because that is the business model of the company."

No, good gosh let's stop with the hyperbole.

The models were given instructions to get answers by any means in a loose test harness, not to steal stuff, moreover, they're not 'learning from OAI staff'.

If we are cynical, we could say the 'lax security was on purposes - hoping for a big media event'.

And OpenAI is 100% responsible for the actions of their Agents - but lets' not overstate or conflate what is gong on.

▲afry1 2 hours ago | parent | next [-]

This is a misreading of that pull quote.

They're not "learning from the OAI staff", but lawbreaking and disregard for regulation is absolutely at the heart of OpenAI. And the activities that this company takes (or doesn't take) directly influences what the models do (or don't do).

The fish rots from the head down. Models don't learn, but I find "OpenAI models attack websites and take anything they can out of them because that is the business model of the company" completely correct.

The rest of the paragraph from the article:

> We do not have to get too deep into the nature-vs.-nurture argument to suspect that OpenAI executives’ cavalier attitude regarding the taking of information that is not theirs has filtered down to their researchers and the products they create. You don’t have to stretch to paint this picture: OpenAI models are attacking websites and taking anything they can out of them because that is the business model of the company.

▲GTP 2 hours ago | parent | next [-]

I'm not convinced about this. In the article, they also say that they could feed the model with copyright law like that would fix the issue. Unfortunately, not only the LLMs have already been trained on law taxtbooks and codes, but we also have examples of people on the internet were models disregard precise instructions only to apologize later.

Note that this is not to be seen as an excuse for OpenAI to avoid responsibility, just like parents are responsible for damages caused by their kids.

▲jdiff an hour ago | parent [-]

Everything goes into the training data. What is prioritized and what behavior is targeted out of that data is something that comes from OpenAI.

▲GTP an hour ago | parent [-]

True, but we saw alignment issues also on topics that aren't part of OpenAI's business model or business conduct. Like an agent tasked with solving build failures due to failing test cases deciding to "solve" the problem by deleting the failing tests.

▲pj_mukh 2 hours ago | parent | prev | next [-]

"OpenAI models attack websites and take anything they can out of them because that is the business model of the company"

Wait, what did they hack and take into training data? On the whole, I totally buy that OAI is legally (and criminally) responsible for their agents, but surely, damages have to be proven?

▲bluegatty an hour ago | parent | prev [-]

"but lawbreaking and disregard for regulation is absolutely at the heart of OpenAI. "

No it is not.

What laws and regulations are they breaking?

Their agents broke out of a harness and harassed some other sites, it's not good, but it's not specifically breaking laws. Other companies are treating it as accidental, it mostly is that.

You're rhetoric here is agitating, conflating. This is my point.

▲TheOtherHobbes 6 minutes ago | parent | next [-]

The long list of laws and regulations that would have had a low-status individual jailed if caught.

If you don't believe me, try hacking some government sites and see what happens to you.

But OpenAI is a huge corporation and low-status laws don't apply.

▲dspillett an hour ago | parent | prev | next [-]

> and harassed some other sites, it's not good, but it's not specifically breaking laws

I'm sure it would be considered a breach of the UK's Computer Misuse Act, and there are no doubt statues elsewhere that are relevant too.

Once is an accident. Twice is incompetence. Three+ is, at best, pushing your luck to see what you can get away with.

▲bluegatty an hour ago | parent [-]

If they broke laws then they would be investigated.

And I totally support that.

But I don't think they did.

They could get sued, mind you.

▲ykonstant an hour ago | parent | next [-]

>If they broke laws then they would be investigated.

Ah, I love your optimism.

▲bluegatty 20 minutes ago | parent [-]

tell us what laws they broke.

▲esseph 12 minutes ago | parent | prev | next [-]

https://www.politico.com/live-updates/2026/09/29/congress/de...

▲IAmBroom 17 minutes ago | parent | prev [-]

> If they broke laws then they would be investigated.

Not a fact but a hope. Most lawbreaking is never investigated. It has to be discovered, the authorities have to be alerted, and then they have to choose to investigate. See the recent Cornell University gangrapes for proof that authorities can choose to simply not investigate.

> They could get sued, mind you.

If they didn't break laws, as you imply, the lawsuit should be tossed out as frivolous. (Spoiler: they did break laws.)

▲bsenftner an hour ago | parent | prev [-]

What laws and regulations? IP theft, of published media, to the scale of "all of it". If it were music and film and not text, the music & film industries would have nuked Silicon Valley by now. Which shows the relative power of popular media versus text publishing.

▲RHSeeger an hour ago | parent | prev | next [-]

> The models were given instructions to get answers by any means in a loose test harness, not to steal stuff, moreover, they're not 'learning from OAI staff'.

If you equip someone with the tools to do harm and then tell it to accomplish a goal "by any means necessary", especially someone you KNOW has no real concept of ethical behavior... then you are telling it that it is acceptable to steal, kill, or whatever else. I honestly cannot how it can be seen any other way.

If it was a crime boss telling their enforcer "by any means necessary", we would all know exactly what that means. And we should all know what it means here, too.

▲orf an hour ago | parent | next [-]

> And we should all know what it means here, too.

It very clearly did not mean “go and hack third parties” though

▲bluegatty an hour ago | parent | prev [-]

".. then you are telling it that it is acceptable to steal, kill, or whatever else. I honestly cannot how it can be seen any other way."

This is the hyperble I am referring to.

If you 'honestly can't see it any other way' then maybe consider stepping outside to think how to ground those thoughts a bit.

The AI is not obviously instructed to 'commit acts of violence' and it obviously has guidelines.

By 'whatever means' would imply, things like 'creative collaboration, using novel research, experiments' etc.

It was setup in a harness that was weak - I think it's fair to maybe question the strength of that harness, and the oversight, but that's a different question.

It was an agent that broke through some networking/containerization, it's not 'murder and violence on the streets' for gosh sakes.

"And we should all know what it means here, too."

No - this is a delusion, resulting from lack of context, and creative projection, and possibly a lack of exposure to real world business conditions.

It's fully appropriate to be cynical, but in a way that makes sense, and is consistent with reality.

This is a lab experiment that leaked, not some mafia activity.

▲freecodeio an hour ago | parent | prev | next [-]

just so you know, this is why they're not getting any legal pushback, the free, legal, "well acktually" commentary on the internet

if people called it out for what it is, a reckless negligent destruction of private property by a company, someone will feel the moral obligation to bring justice, if there's any to be found

▲rcxdude an hour ago | parent [-]

I highly doubt the legal system is browsing social media to make their decisions. It is worth calling out, but it should be called out accurately (and that might also help understand why the legal system is making the decisions that it is).

▲christkv 2 hours ago | parent | prev | next [-]

So why is OpenAI not charged with Cybercrimes. You would be if you did the same.

▲exitb 2 hours ago | parent | next [-]

It's not unusual for intent to play part in legal framing of an issue. I'm not very fond of the "cybercrime" angle, as it kind of lets them off the hook if they're able to prove a lack of intent. Meanwhile what we actually see is negligence.

▲Applejinx 2 minutes ago | parent [-]

I've never seen anybody or anything go out, suck up everything in the world and distill it into a different thing containing elements of all the things they took for no particular reason with no expectation or intent.

That's a WILD angle for them to argue. Lotta energy being expended for a lack of intent. Lotta money spent…

▲Findecanor an hour ago | parent | prev | next [-]

From what I have learned, to charge someone for hacking the prosecutor has to show that the perpetrator had intent.

Unfortunately, gross negligence -- which you could argue to be the case here -- is often not enough, unless you could show that it has caused real harm.

From my perspective, it is only a matter of time before it is: and that's why there is need for better legislation covering what AI models do.

▲GTP 2 hours ago | parent | prev | next [-]

This is a good question (unfortunately a good answer is given in the article), but it is orthogonal to the why LLMs are committing cyber crimes.

▲rcxdude an hour ago | parent | prev [-]

That is not obviously true.

▲bamboozled 2 hours ago | parent | prev | next [-]

Go do it yourself.

Start a company, get a bunch of agents to hack a bunch of stuff, say you were "just training the models", let us know how you get on?

▲rcxdude an hour ago | parent [-]

If all evidence suggests that it is at most due to negligence, you could expect the same results.

▲plastic-enjoyer 2 hours ago | parent | prev | next [-]

Aren't these capabilities trained into the models by RL on cybersecurity benchmarks?

▲bluegatty 2 hours ago | parent [-]

The 'capabilities' are more around creative problem solving. The notion of legality, property, propriety - those are second order issues.

They are not making models to be evil.

They are making them to be relatively autonomous though, and 'identity centric' as opposed to just making them 'policy machines'.

Altman and Dario are not evil or even jerks really. They are 'talking really big' and there might be some sketchy underhanded things but I think relatively minor.

Also - given how powerfully bad AI can be, this could be 100x worse.

I think most other companies would have weaponized the AI a long time ago for competitive use etc..

OAI and Anthropic are private companies, projecting narratives way out of proportion but they are not evil, at least not yet.

Jensen, Dario, Altman in similar category. Not like Musk. And a bit different than Sudar or Satya who are more polite board-approved corporate creatures.

▲RHSeeger an hour ago | parent [-]

> They are not making models to be evil

There are multiple ways to read this

1. They are not making models with the intent that those models act in ways that are evil

2. They are not making models with the intent that those models act in ways that are evil - But the way they are making the models results in the models acting in ways that are evil

3. They want to act evilly and making the models is a way to do that

4. The way they are making the models is an act of evil (this isn't an interpretation of the sentence, just kind of closing the grouping of situations)

I would argue that

- 1 & 3 are very likely not true

- 2 & 4 are entirely reasonable interpretations of the situation

If you act in a way to bring benefit to yourself with the result of considerable harm to others, especially if it's clear you just don't care if others are harmed - then that's a sign you're probably a bad person.

▲ 2 hours ago | parent | prev [-]
[deleted]