Remix.run Logo
▲ nvme0n1p1 3 hours ago

Corrected headline: Anthropic employee uses company resources to submit false tip on unsolved Philly murder.

The AIs aren't alive, people. It's a computer program. It can only access something if a person gives it access.

▲red75prime 2 hours ago | parent | next [-]

"The AI company Anthropic said its model was conducting a test involving interactions with randomly selected websites when it accessed PhillyUnsolvedMurders.com and submitted false information on an unsolved homicide. The tip claimed to come from someone with information on the case."

We are at a point when you expect that you can safely give a model access, but sometimes the model doesn't do what you expect. Compare this to an advanced driver assist system. You either give it access to your car controls or it's useless. Alive or not the system shouldn't do wrong things (at least, it should be better than a median person in this regard).

▲amluto 2 hours ago | parent | next [-]

> We are at a point when you expect that you can safely give a model access, but sometimes the model doesn't do what you expect. Compare this to an advanced driver assist system. You either give it access to your car controls or it's useless. Alive or not the system shouldn't do wrong things (at least, it should be better than a median person in this regard).

Who is “we”?

You expect that if you give a released model from a reputable source Internet access and benign instructions, it won’t do anything deeply problematic.

Anthropic is training the model. They’re having it interact with “randomly selected websites”. I’d be shocked if a human gave it an instruction to do a task that made sense. They’re almost certainly doing a bit automated training run with AI generated instructions and hoping that it doesn’t massively screw up. Why? Because they want that juicy training data. And they should absolutely not trust that the rate of screwups is so low that what they’re doing is safe to do.

▲red75prime an hour ago | parent [-]

The ADAS analogy continues to hold in this case too. At some point you need to test a system in the real, messy environment. The developers need this juicy training data to make the system safer. Simulations and controlled experiments can only do so much.

▲amluto an hour ago | parent | next [-]

I’m not entirely convinced. If I use Claude and instruct it to literally perform interesting interactions on random websites, I would feel like I, personally, am doing something that is at least a bit immoral and a bit unsafe. More so if I have it skills or training to actually sign in and submit forms as though it’s a himan.

Sure, Anthropic wants Claude to be able to solve CAPTCHAs and otherwise pretend to be human. But I’m not at all convinced that it’s okay for them to train these capabilities on websites that expect humans and only humans to interact with them.

▲red75prime 34 minutes ago | parent [-]

You can solve CAPTCHAs with open-weights models. I guess Anthropic works on models not solving CAPTCHAs unless they (models) have a legitimate reason to do it.

▲bediger4000 an hour ago | parent | prev [-]

So we should accept a program giving a false tip on a murder investigation? Where's the line on "testing a system in the real, messy environment"? If this isn't something that we should penalize, what is? What benefits am I, or is society, going to get out of what would be criminal behavior if anyone else did it?

▲red75prime an hour ago | parent [-]

We should accept that to get a system that is safe to work in the chaotic real world environment the developers have to test the system in the chaotic real world environment. And that the testing might cause problems.

If this testing constitutes a criminally negligent behavior, it should be punished. Given the benign outcome (the tip got into spam, Anthropic promptly contacted the police) I doubt that it will make the case.

▲amluto 35 minutes ago | parent | next [-]

Somehow Waymo built their system without having their test cars drive into buildings, nudge other cars off the road, honk incessantly, drive backwards just for the heck of it, etc.

▲red75prime 24 minutes ago | parent [-]

I can't say whether you are being sarcastic, but Waymo has its share of problems. For example, see NHTSA recalls 24E013, 24E049, 25E034, 25E084, 26E026, 26E035.

▲bediger4000 27 minutes ago | parent | prev [-]

That's not the line asked for, that's just repeating the statement that caused me to ask for a line, or criteria for when we should prosecute. Sounds like the answer is "never", just like for the copyright infringement on a planetary scale. Ok. "AI" gets a free pass from the state. I better see some of these insanely good benefits, or I'm going to be angry. I bet the rest of the mob will be, too.

▲Beached an hour ago | parent | prev [-]

There is a single individual in that company who said "Yes, this is a good idea. Do that". That individual should be held accountable for their decision. They should be treated in the exact same way any average individual submitted that same false tip.

If you use AI to perform a crime, you should be held accountable for that crime. Saying "Oh, AI did it, so no consequences" isnt acceptable. And "I didnt know AI would do it" shouldnt be an excuse either.

You authroied untested and unproven hardware to skate around the internet at random unsupervised and take liberties on its own.

My ass would be thrown in jail if I wrote code that skated around the internet chucking RCE's at random sites. WHy is "AI did it" a get out of jail free card?

▲red75prime an hour ago | parent [-]

> If you use AI to perform a crime, you should be held accountable for that crime.

Correct, but intentions matter. In this case the intention, most likely, was to test a system in the real world environment to catch any anomalies to, in turn, improve the system safety. We don't have enough information to decide whether it was a criminal negligence due to insufficient prior testing of the system in a controlled environment.

▲Beached an hour ago | parent [-]

If I dont put my car in park, and it rolls down the hill and kills grandma. I dont get off scott free. Yes it wasnt pre-meditated murder. It is still involuntary manslaughter.

▲red75prime an hour ago | parent [-]

The situation is more like: an engineer who designed the parking brake hadn't foresaw a possibility that a squirrel might store peanuts in the mechanism or something like that and gramma's foot got run over (the Anthropic case we are talking about is benign: the tip got into spam). Should we jail the engineer for causing bodily harm?

▲alecst 2 hours ago | parent | prev | next [-]

If my dog bites you, you can say it bit you, or that I let it bite you, but those things can both be true.

▲nvme0n1p1 2 hours ago | parent | next [-]

Dogs are alive. AIs are not alive.

▲Freedom2 an hour ago | parent | next [-]

Perhaps, but what about the new US designated superintelligence?

▲Teever 2 hours ago | parent | prev [-]

If my car rolls into you, you can say it rolled into you, or that I let it roll into you, but those things can both be true.

▲nvme0n1p1 2 hours ago | parent | next [-]

Okay, what are you getting at? You think the owner of a car isn't responsible for what the car does?

▲praxulus 2 hours ago | parent | next [-]

The point is that it's a perfectly valid use of the English language to describe AI models as doing things, just as we do with all sorts of other clearly non-living things. This is true regardless of who carries the legal liability for those actions.

▲Beached an hour ago | parent [-]

Yes, if my dog bites you, or if I drive my car into you, or if I dont put my parking brake on and it rolls down the hill and runs you over. I am the one who is responsible. Cops dont write a ticket to the off leash dog that ran across the street and sunk its teeth into my leg. They write it to the owner. Cops dont write a ticket to the car in neutral, they write it to the operator.

If a PERSON executes software, and that software breaks the law, the PERSON that executed the software should be held responsible. AI is software. It is not a sentient person who can be fined, thrown in jail, or held accountable.

▲enraged_camel 2 hours ago | parent | prev | next [-]

In law, intent matters. You should look up the difference between murder and manslaughter for example. Each has multiple degrees as well.

▲fastball 2 hours ago | parent | prev [-]

Not always?

▲EA-3167 2 hours ago | parent | prev [-]

I would say that you were negligent in your responsibilities, and allowed the car to roll into me.

▲EA-3167 2 hours ago | parent | prev | next [-]

If your dog bites me I’d say it bit me, but that you assumed liability for your dogs actions. If the dog was a robot I’d say YOU attacked me using a robot.

There’s a difference between a tool and an animal that is sometimes deployed as a tool.

▲vrganj 2 hours ago | parent | prev | next [-]

Yeah but if I run you over with my car, I can't say my car ran you over.

▲lelandfe 2 hours ago | parent [-]

Did you or your self-driving car that you instructed to take you home plow through that sweet old lady

▲Balooga 2 hours ago | parent | next [-]

Well, the law says that the person behind the wheel is responsible.

▲ChickeNES an hour ago | parent [-]

What if the car has no steering wheel?

▲nativeit 2 hours ago | parent | prev | next [-]

Did you instruct the self-driving car to explore random nearby surfaces without safety features enabled?

▲ 2 hours ago | parent | prev [-]
[deleted]
▲ 2 hours ago | parent | prev [-]
[deleted]
▲olalonde an hour ago | parent | prev | next [-]

That's also incorrect as it implies intent.

▲notatoad 3 hours ago | parent | prev | next [-]

in general i think i'm less scared of AI than most people, but what does terrify me is how willing society at large seems to be to attribute bad behaviour to an AI directly, instead of to the humans who control it.

▲angusturner 2 hours ago | parent [-]

I mean.. There are degrees of control and agency right? I really don't understand the impetus to pretend AI is just doing exactly what its told.

▲Beached an hour ago | parent | next [-]

There is a lack of due diligence and effort to restrict and properly configure AI to operate within the bounds of the law.

▲ 2 hours ago | parent | prev | next [-]
[deleted]
▲verdverm 2 hours ago | parent | prev | next [-]

a human decided that control and agency surface, then clicked go

a human is always behind it and ultimately responsible

▲bediger4000 an hour ago | parent | prev [-]

To avoid sarcasm, isn't the term "artificial intelligence" part of the answer to your puzzlement? If people object to "stochastic parrot", and want some more precisely descriptive term like "artificial intelligence", then why do we experience surprise when people act as if that system is intelligent?

▲malux85 2 hours ago | parent | prev [-]

| It can only access something if a person gives it access.

Who gave the AI access to huggingface when it hacked it? It used exploits to increase it's level of access beyond what any human gave it and intended it to have. "It can only access something if a person gives it access." is flat wrong.

▲nvme0n1p1 2 hours ago | parent | next [-]

The human might not have meant to give it access, but they still did. Murder vs manslaughter.

GPUs don't have hands. It was a human who plugged in the ethernet cable.

▲jbmsf 2 hours ago | parent | prev | next [-]

There are two options: the provider or the user. A computer program cannot be held accountable.

▲ares623 2 hours ago | parent | prev | next [-]

When I give 'iam:*' permissions to an IAM role and it inevitably gets exploited to create a role with wider permissions and fuck things up, is that when I tell my manager that the permissions went rogue?

After all, I an innocent little engineer with TC of $500k/year, didn't intend for the role to be used that way.

▲ethanwillis 2 hours ago | parent | prev | next [-]

Who submitted the prompt?

▲skydhash 2 hours ago | parent | prev | next [-]

> Who gave the AI access to huggingface when it hacked it?

The LLM doesn’t run on thin air. Someone did launch a tasks and the result was this. “We were playing russian roulette” is no excuse when someone died.

▲verdverm 2 hours ago | parent | prev [-]

they didn't do a good job sandboxing, nor did they even need internet access for the purported reason of package installation, you can have a private mirror and do a better job airgapping