| ▲ | devindotcom 6 hours ago |
| If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings. I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. We can't wait until serious harm is done like the disruption of medical or social services. |
|
| ▲ | eikenberry 5 hours ago | parent | next [-] |
| > I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them. |
| |
| ▲ | athrowaway3z 5 hours ago | parent | next [-] | | Jensen has proclaimed in interviews that existing laws are enough and these labs should be held liable if they break things or sell unsafe tools. NVIDIA has bought HuggingFace. Jensen, in my irrational hope he is susceptible to random comments on HN, should grow some balls and do the world a huge favor, by suing OpenAI to set the legal precedence. | | |
| ▲ | beloch 4 hours ago | parent | next [-] | | Nvidia has a huge stake in OpenAI, both in terms of them being one of Nvidia's biggest customers and also via direct investment. After HuggingFace was hacked and they expressed the position that they were the forgiving sort, for a price, there was a distinct possibility that HuggingFace would become a vocal shakedown artist that would start protesting at inconvenient times until silenced by more money, especially if they get hacked again. By complete coincidence, Nvidia took the one move that silences HuggingFace for good. Nvidia isn't going to sue OpenAI. No chance. | | |
| ▲ | yoavm 3 hours ago | parent [-] | | Who will though? At this point it seems like a huge chunk of US economy growth can be attributed to AI. Bubble or not, I guess very few would benefit from bursting it? | | |
| ▲ | beloch 3 hours ago | parent [-] | | Are you suggesting industry might not regulate itself? This is unthinkable! |
|
| |
| ▲ | eleventen 4 hours ago | parent | prev | next [-] | | Jensen is wish-casting as hard as anyone has ever casted a wish. That EK show interview made me throw my phone. | | |
| ▲ | baq 4 hours ago | parent [-] | | Is it the one in which he said ‘it’s just software’ over and over? Felt like the guy was coming from a parallel universe | | |
| ▲ | jimbokun 4 hours ago | parent [-] | | “The atom bomb is just the same process the sun uses to generate the energy that gives us all life! You don’t hate the sun do you?” |
|
| |
| ▲ | devindotcom 3 hours ago | parent | prev | next [-] | | a fine hope if unlikely. but I wanted to also note in friendly fashion that the word you want is precedent (or precedents) - precedence has a connotation of "first among" rather than precedent's "came before." | |
| ▲ | taariqlewis 4 hours ago | parent | prev [-] | | I think a good bunch of Jensen's revenues are coming from OpenAI so that's not happening. | | |
| ▲ | goodluckchuck 4 hours ago | parent [-] | | It's all for show. The police won't / can't prosecute, because they'd need to prove that a crime was committed... and all we have are salespeople saying how great their product is. I'm not saying AIs can't be used for crime, but... if none of the parties involved are really complaining, then there probably wasn't any real crime... just a performance. |
|
| |
| ▲ | fourside 5 hours ago | parent | prev | next [-] | | Hope this isn’t too nitpicky but law enforcement is (a component of) regulation. But yes I don’t think progress is blocked on additional regulation. This breaks current laws. And I think more to your point new regulation doesn’t matter if we don’t enforce the ones we have today. | | |
| ▲ | forshaper 4 hours ago | parent [-] | | It is a broader, pre-existing problem. For example, most truck drivers in some states who don't tie down their rebar are not stopped, and it doesn't come up until another vehicle is actually hit. |
| |
| ▲ | XenophileJKO 5 hours ago | parent | prev | next [-] | | I think we have to distinguish between compromising a network and using public apis in a way that might be counter to their intent. We also need to delineate between usage that impacts other users and usage that does not. My opinion is people are getting really quick at jumping on the bandwagon and lumping all this together. They are very different types of issues and impacts. | | |
| ▲ | helterskelter2 5 hours ago | parent | next [-] | | > distinguish between compromising a network and using public apis in a way that might be counter to their intent. I believe weev got in legal trouble under the CFAA for this very thing with his 2010 AT&T escapade. AT&T had all that data sitting on a public server with no authentication necessary, just a SIM ID to get that customer's PII. Truthfully AT&T should have been hit with negligence...you don't secure a bank vault with a screen door, but we don't hold anyone accountable for other people's data in America. | |
| ▲ | marshray 28 minutes ago | parent | prev | next [-] | | What is "exceeding authorized access" if not "using APIs in a way counter to their intent"? | |
| ▲ | paimapi 5 hours ago | parent | prev | next [-] | | is that relevant here? let's say I make a million requests to the APIs of open-source, community projects. that wouldn't be seen as being akin to a malicious DDOS? at the very least, these corporations are essentially being subsidized by community-funded server capacity to make these requests. like other private corporate APIs, they should be charged per-request. until then, this kind of 'accidental' DDOSing should be made illegal and treated accordingly coming to the defense of these companies just has the net effect of eroding public community projects, increasing their costs, and will push us even more into walled corporate gardens | |
| ▲ | pessimizer 4 hours ago | parent | prev [-] | | I propose that we don't reconceptualize either hacking or copyright violation just because rich people want to do it now. I also propose that we don't ignore the RICO statutes. If you want to make those laws sane, so be it; I hate them. But the only reason there's some pumped-up urgency right now is because rich people want to urgently do whatever the hell they urgently want to do. People have gone to jail for using public APIs in a way they weren't intended to be used. Make it a big deal then. |
| |
| ▲ | jimbokun 4 hours ago | parent | prev | next [-] | | We already went through this with food and drug safety. It’s much cheaper and more effective to regulate those things before people are harmed, instead of harming people first then allowing them to sue for damages after. | | |
| ▲ | MengerSponge 3 hours ago | parent [-] | | We can walk and chew gum at the same time. Charge the criminal action, fine the bad actors to help make injured parties whole, and regulate the technology to protect against future harms. These guys will tell you their industry is more dangerous than nuclear power, and we regulate the living shit out of nuclear power. If you think models can't be regulated, look up the export controls on MCNP and tell me how that's different. |
| |
| ▲ | notyourwork 4 hours ago | parent | prev | next [-] | | It’s quicker to start with enforcement of existing laws. In parallel, we can work on regulation. There always will be first to market rebels and laws are meant to be enforced to ensure safety of people. | |
| ▲ | VladVladikoff 5 hours ago | parent | prev | next [-] | | What if that’s their whole goal? Slap some regulations on it, then lobby the hell out of it to make sure their align best with shutting down access to open models. | | |
| ▲ | pixl97 3 hours ago | parent | next [-] | | Just get over there being open access models in the future unless they are highly regarded. 'Smart' LLMs will be classified as munitions and you and I will get scraps. Even better is if you run Smart models illegally you have a nice visit from the 4chan party van. | |
| ▲ | lenerdenator 5 hours ago | parent | prev | next [-] | | If it's their actual goal, we go from a "gosh darn it, our safety protocols just weren't enough." to employees of OpenAI, maybe including their C-suite, conspiring to reach political goals through hacking, which means a few decades in federal prison if someone got a jury to agree with the charge. | | |
| ▲ | Applejinx 4 hours ago | parent [-] | | Or straight up terrorism. These are people who already see a future superintelligence as being a terrorist actor on the scale of state actors, they just side with the terrorist. They may be getting a head start on that. I think 'better become terrorists so the future terrorist AI will like us' is sheer mental illness, but I see how it aligns with their alignments. | | |
| |
| ▲ | jMyles 4 hours ago | parent | prev [-] | | Although we'll probably never see evidence, I think this is almost certainly what is happening. |
| |
| ▲ | JumpCrisscross 4 hours ago | parent | prev | next [-] | | It really is weird that OpenAI is causing so much chaos when e.g. neither Anthropic nor any open-source models are. | | |
| ▲ | lkjdsklf 4 hours ago | parent | next [-] | | Anthropic has had this happen at least once. They didn't even realize it happened until openAI captured headlines and they started looking more carefully at past history. None of the frontier labs are behaving responsibly when it comes to this stuff. OpenAI seems to have it happen more often, but this is one of those situations where 1 time is too many. | |
| ▲ | blurbleblurble 4 hours ago | parent | prev [-] | | If only there was a functioning FCC to investigate potential for foul play in marketing? Surely if any aspect of these episodes turned out to be mischaracterized, let alone staged, there should be consequences, no? | | |
| ▲ | JumpCrisscross 4 hours ago | parent | next [-] | | > FCC to investigate potential for foul play in marketing? ...why would this be an FCC issue? > Surely if any aspect of these episodes turned out to be mischaracterized, let alone staged, there should be consequences, no? "Any aspect"? No. (Is there a Betteridge's law for statements following "surely"? If not I'm calling it Rumack's Razor [1].) And we have no evidence so far anything has been staged, much less to the detriment of telecommunications consumers. [1] https://screenrant.com/airplane-best-quotes-ranked-dont-call... | | | |
| ▲ | jeremyjh 4 hours ago | parent | prev [-] | | It isn’t staged, and it isn’t marketing. It doesn’t reflect well on OpenAI and isn’t going to help their IPO. AI is more dangerous than we expected, sooner than we expected. | | |
|
| |
| ▲ | ajross 4 hours ago | parent | prev | next [-] | | > Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them. Refusal on the part of the government to enforce laws that "would suffice" is clear evidence that the regulatory regime is, in fact, insufficient. That's why we have regulatory authorities at all, if you think about it. Local district attorneys could be handling a ton of cases about drug testing and environmental damage and air travel safety. But they don't, because that stuff's hard and their job is to put burglars in jail. | |
| ▲ | ForHackernews 5 hours ago | parent | prev | next [-] | | The Florida AG is trying to https://www.politico.com/news/2026/09/28/florida-injunction-... | | |
| ▲ | gruez 5 hours ago | parent | next [-] | | But not for hacking, apparently. >Uthmeier is seeking an injunction against OpenAI that would prevent the company from advancing new AI models without third-party approved protections, and cut off minors from using its popular chatbot. | | |
| ▲ | VoidWhisperer 4 hours ago | parent [-] | | Regarding that last bit, it feels like Florida is headed towards a point of trying to say 'minors should not be able to use the internet at all' since they are trying to force putting age verification infront of more and more things. Don't get me wrong - while I disagree with making people fork over personal info just to access inappropriate websites - I can see the reasoning there a bit more than 'you shouldnt be able to use this ai chatbot until you are 18' |
| |
| ▲ | asawfofor 4 hours ago | parent | prev [-] | | Here’s a suit filed in San Francisco https://lasst.org/wp-content/uploads/2026/09/LASST-v.-OpenAI... |
| |
| ▲ | micromacrofoot 5 hours ago | parent | prev | next [-] | | At this point we'd need to stop frontier labs to give law enforcement a chance to even begin to understand what they're looking at | | |
| ▲ | nemomarx 5 hours ago | parent | next [-] | | How much do they need to understand? Say "unauthorized access happened, this lab is responsible for it, here are the fines". The state didn't need to understand networking tech to threaten Aaron Schwartz so why do they need to understand here? | | |
| ▲ | 4 hours ago | parent | next [-] | | [deleted] | |
| ▲ | pixl97 3 hours ago | parent | prev [-] | | Eh... you don't seem to understand the difference between some individual LEO can go after vs a multi billion dollar industry. Law enforcement gets really careful around big businesses because they know they'll get smacked for every tiny transgression they make. Meanwhile they'll screw with individuals with impunity. |
| |
| ▲ | pessimizer 4 hours ago | parent | prev | next [-] | | Throw a bunch of them in jail for hacking and organized crime, and they'll self-regulate. | |
| ▲ | reaperducer 4 hours ago | parent | prev [-] | | At this point we'd need to stop frontier labs to give law enforcement a chance to even begin to understand what they're looking at So what? Are you positing that tech companies should be above the law? Non-trillion-dollar tech companies get cease-and-desist orders from the legal system every day. Just because you're a tech company doesn't mean you get a pass. | | |
| ▲ | micromacrofoot 3 hours ago | parent [-] | | They're currently acting above the law because the law isn't keeping up, just because you're a tech company doesn't mean you get a pass... but wow there are a lot of passes being given right now |
|
| |
| ▲ | gruez 5 hours ago | parent | prev [-] | | >All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them. Source? The CFAA for instance uses terms like >[...] having knowingly accessed a computer without authorization [...] >[...] intentionally accesses a computer without authorization [...] which is tricky to apply to this case, because obviously didn't intend on hacking huggingface or whatever, even if you think their security measures are underbaked. Moreover, despite the cynicism that openai is immune to prosecutions because they make too much money or are in bed with the DoJ, the fact that no state DAs are prosecuting them, despite how salient of an issue AI is to voters, is plenty of reason to suspect that it's not as simple as "simple law enforcement would suffice". | | |
| ▲ | ofjcihen 4 hours ago | parent [-] | | >obviously didn't intend on hacking huggingface or whatever You can’t say this until it’s tried in court and found to be true. Additionally, I have to remind everyone that “intent” is not someone admitting they meant to do x. It can be established in many ways, including through repeated actions. |
|
|
|
| ▲ | Terr_ 5 hours ago | parent | prev | next [-] |
| Another amusingly-useful analogy: > “Adding powerful computer hacking tools to a harness, and then allowing it to run an LLM-powered Ask → Act → Report for days on end, with no attempt to monitor what it’s up to, is spectacularly negligent,” Newport concludes—like “strapping a weedwhacker to your dog to see if it will end up cleaning the overgrowth in your backyard.” If that plan were to go awry, you’d be laughed at for saying that your dog-weedwhacker “agent” had “gone rogue.” The obvious truth was that you’d simply decided to unleash chaos. -- https://www.newyorker.com/culture/open-questions/can-ai-go-r... |
|
| ▲ | teagee 6 hours ago | parent | prev | next [-] |
| None of what Wikimedia accuses OpenAI of seems technically novel, aside from having AI do the bidding. I can't imagine a company doing these things in the past and maintaining any sort of reputation. Is it really a matter of adding new regulation, or just treating them the way any other company would be treated? |
| |
| ▲ | jstummbillig 5 hours ago | parent | next [-] | | Well, in the past, there was probably only a very small number of cases where some party hacked an institution and then worked with them to remedy the situation to the best of their abilities. Which is not to say that any of this is okay and should just be excused, but failing to recognize this fairly significant difference is probably not a great start to any discussion about the issue. | | |
| ▲ | nemomarx 5 hours ago | parent | next [-] | | If you break into my house and then work with me to the best of your ability to pay me back or repair the window, does that change the potential of your being charged with a crime? It could change the sentencing maybe, I'm not sure. | | |
| ▲ | jstummbillig 4 hours ago | parent | next [-] | | > If you break into my house and then work with me to the best of your ability to pay me back or repair the window, does that change the potential of your being charged with a crime? Yes, it does, because the damaged party is less likely to press charges. And when it came to sentencing, like you said, how the damaging party handled themselves would also be considered (in most western jurisdictions). | |
| ▲ | someonebaggy 4 hours ago | parent | prev [-] | | [flagged] | | |
| ▲ | pixl97 3 hours ago | parent [-] | | Now switch it to "your dog broke in and destroyed stuff", ya it's still damages but that have to be paid for, but crime gets much harder to prove. |
|
| |
| ▲ | 5 hours ago | parent | prev [-] | | [deleted] |
| |
| ▲ | jimbokun 4 hours ago | parent | prev | next [-] | | Well I think OpenAI’s reputation is also shot but it’s irrelevant to their valuation. | |
| ▲ | avaer 6 hours ago | parent | prev [-] | | Would be good for the supreme court to rule on a "blame the rogue agent" case. Then we would find out if the argument doesn't hold (in which case there should be liability and dire consequences for the labs), or the argument holds (in which case YOLO, AI labs can blame the AI and we can all do it too). At least that would make things consistent. | | |
| ▲ | JumpCrisscross 5 hours ago | parent [-] | | > Would be good for the supreme court to rule on a "blame the rogue agent" case Have any of the private hacking victims sued? Maybe OpenAI is furiously settling in the shadows? |
|
|
|
| ▲ | gruez 5 hours ago | parent | prev | next [-] |
| >If a truck driver doesn't tie down their rebar then it flies out all over the highway, we don't call it "rogue rebar," we correctly identify the responsible party and take appropriate measures, such as suspending their license or criminal proceedings. That only works when the dangers are well known that you can establish what the baseline amount of care is. Otherwise it just becomes a run of the mill "accident" where you might be on the hook in civil court (ie. you have to pay any damages you caused), but aren't criminally responsible. For instance, if a semi-truck's tires randomly explodes. |
| |
| ▲ | red-iron-pine 4 hours ago | parent [-] | | but even if it randomly explodes there are safeguards -- did they get an inspection, can they prove there wasn't negligence? if someone died because of an exploding tire there very well be criminal charges | | |
| ▲ | SoftTalker 4 hours ago | parent | next [-] | | For criminal charges, a prosecutor would have to prove there was negligence, which is a higher bar. | |
| ▲ | pixl97 3 hours ago | parent | prev [-] | | No, there will almost never be criminal charges in a case like that. It will be a wrongful death suit. | | |
|
|
|
| ▲ | againstapples an hour ago | parent | prev | next [-] |
| What additional things would be needed to classify any future incidents as rogue? |
|
| ▲ | INTPenis 5 hours ago | parent | prev | next [-] |
| Yeah it's complete buzzword inflation to get more venture capital. Sometimes they write an MCP for their AI, and the AI finds vulnerabilities in their own MCP, so they call it rogue. Because they didn't properly audit their own MCP code. |
|
| ▲ | jimbokun 4 hours ago | parent | prev | next [-] |
| I vote for Sam Altman personally receiving the same penalty that some guy living in his parents basement would get if they performed the same activities as the OpenAI bots. |
|
| ▲ | boringg 4 hours ago | parent | prev | next [-] |
| In this example you are describing the company that drives the vehicle, not the company that makes the rebar. OpenAI is the one who made the rebar, but not necessarily the one driving the vehicle. I get your point though. |
| |
| ▲ | RunSet 4 hours ago | parent | next [-] | | > OpenAI is the one who made the rebar, but not necessarily the one driving the vehicle. More like the company that sells defective ratchet straps. "Drive faster! You don't want to be left behind!" | |
| ▲ | breakwaterlabs 4 hours ago | parent | prev | next [-] | | In almost all of these cases, it is both: the labs are operating the agents, while developing them, and committing their CFAA felonies in the process. | |
| ▲ | surgical_fire 4 hours ago | parent | prev [-] | | Just to drive the point home, in the real world, if the rebar fell because of lack of quality control, the company that made it would be responsible. If it was for lack of maintenance, the driver would be responsible. The language of a rogue rebar is as absurd as the language of rogue agents. OpenAI is horribly negligent, and in a sane world its administrators should be facing legal consequences. |
|
|
| ▲ | breakwaterlabs 4 hours ago | parent | prev | next [-] |
| "The law" already exists, civil suits are a thing, and we no more need targetted AI regulation than we need targetted truck-rebar-incident regulation. These incumbent labs are angling for regulatory capture by stirring up hysteria and suggesting that existing laws are insufficient. Don't do their job for them, first test whether there's actually a legal gap here. |
|
| ▲ | tencentshill 4 hours ago | parent | prev | next [-] |
| That's how America works. We wait until the harm has slapped us in the face and then maybe put a few ground rules down. |
| |
| ▲ | SoftTalker 4 hours ago | parent [-] | | And give the violator a seat at the table when the rules are written, no doubt. |
|
|
| ▲ | Kim_Bruning 4 hours ago | parent | prev | next [-] |
| And if it's an aircraft we call an air-crash investigation and apply just culture. [1] Meanwhile the AI companies are openly and forthrightly admitting [2] that they are at-this-time insufficiently competent to ship this new and funny sort of rebar [3] and are asking to be allowed to slow down so they can develop proper procedures. Meanwhile POTUS seems ... somewhat disinclined ... to grant their petitions [4] . We can safely conclude that opinions are divided on the best course forward. [1] https://en.wikipedia.org/wiki/Just_culture [2] https://darioamodei.com/post/we-must-pace-the-frontier [3] https://en.wikipedia.org/wiki/Shoggoth [4] https://www.aljazeera.com/news/2026/9/14/trump-says-calls-fo... |
|
| ▲ | iririririr 5 hours ago | parent | prev | next [-] |
| Never understood why "classic crime" done with a computer always require a new legislation. But that is true for a long time. "hackers steal from bank", is usually just the good old "employee paid for credentials" but via email. "uber" is just the good old "labour tax evasion" but with an app. etc. |
| |
|
| ▲ | grafmax 5 hours ago | parent | prev | next [-] |
| Seems like regulation will just be an excuse for them just to end up policing themselves and get the regulatory capture they've been begging for. Have they faced any consequences for the AI worms they've released? It's not like there are no laws around that already. The problem isn't lack of laws; the government works for the plutocrats, not for us. |
|
| ▲ | 5 hours ago | parent | prev | next [-] |
| [deleted] |
|
| ▲ | doctorpangloss 6 hours ago | parent | prev | next [-] |
| uh, my dude, millions of people break moving vehicle codes across the country every day with no consequence. in San Francisco some lady killed a family of 4 with, essentially, no consequences, she got away with straight up murder, she gets her license back. every community in california, you can more or less legally commit murder so long as you do it in a car and claim you were confused about the accelerator and the brake. so i think you're invoking one of the worst possibly comparisons you could. |
| |
| ▲ | thraway3837 6 hours ago | parent | next [-] | | Yup, worst possible comparison. 40,000 people die from car accidents. That doesn't even cover pedestrians, cyclists. You know what the penalty is for murdering someone with a car? nothing. you get to go back to society like nothing happened. Oh and that lady that murdered 4 members of an entire family? The judge chose not to pursue charges, and her family in the meantime did an asset transfer so that nothing could be pursued with in civil court. | | |
| ▲ | Legend2440 5 hours ago | parent | next [-] | | The position of the legal system is that car accident deaths are not murder. It is extraordinarily rare for drivers to see criminal charges unless they are drunk. It's a matter for civil court. >her family in the meantime did an asset transfer so that nothing could be pursued with in civil court. News articles are reporting that the asset transfer has already been reversed. That kind of stunt never works - courts aren't stupid and they don't like it when you play games. https://sfstandard.com/2026/03/20/mary-lau-sentenced-probati... | |
| ▲ | nancyminusone 5 hours ago | parent | prev | next [-] | | There's way too many TV lawyer commercials and billboards to suggest the penalty is "nothing". Those advertising dollars come from somewhere. | | | |
| ▲ | someonebaggy 5 hours ago | parent | prev [-] | | I remember a case from Germany where an elderly lady chose to speed down the pedestrian sidewalk and bike lane and mowed down a whole family in central Berlin. 4 deaths I think, no charges, no suspension. |
| |
| ▲ | iAMkenough 6 hours ago | parent | prev | next [-] | | I agree, since you can legally run over people in my state now. They should have used an example like attacking a foreign nation’s healthcare systems and not realizing it for months due to poor network monitoring practices. https://www.nytimes.com/2026/09/29/world/asia/openai-austral... | |
| ▲ | redanddead 6 hours ago | parent | prev [-] | | what the fuck, SF | | |
| ▲ | soco 5 hours ago | parent [-] | | You probably mean "what the fuck, USA" and even that would be wrong, because another commenter mentioned a case in Germany, and I know about a driver who killed a cyclist (which I knew) in Switzerland and was fined like 500CHF. |
|
|
|
| ▲ | dyauspitr 5 hours ago | parent | prev [-] |
| [flagged] |
| |
| ▲ | tene80i 5 hours ago | parent | next [-] | | "Pipe down" is disgraceful language. Conduct yourself better. | | | |
| ▲ | miltonlost 5 hours ago | parent | prev [-] | | You and Lord Pharquad are very similar. Some people may die, but such a sacrifice you're willing to make. | | |
| ▲ | dyauspitr 5 hours ago | parent [-] | | I guess the difference is I’m also one of the people that might die unlike Lord Pharquad and I still say bring it on. |
|
|