Our legal system isn’t ready for machines that act on their own.

61 points•pseudolus•7 days ago•49 comments•

49 comments

drywater27 days ago
>Our legal system isn’t ready for machines that act on their own.

Technically, the code is owned and deployed by AI companies which make the AI companies 100% responsible. I'm not sure how is code written by LLMs different than any other kind of code. If somebody hacked just like OpenAI's agents did, he would've ended up in prison right away.

nazgulsenpai6 days ago
Maybe I'm too cynical but the same AI companies that have pretty much endless lobbying dollars, massive government contracts, have the ear of just about every powerful politician and bureaucrat in DC, are influencing the laws and regulations. Add judges that don't understand the technology to that and it doesn't seem likely that we will ever see any actual consequences, unless something catastrophic happens and those same politicians and bureaucrats need a scapegoat. If they ever do have "consequences" it will be some trivial fine.
sellmesoap6 days ago
One recent example of a scapegoat https://news.ycombinator.com/item?id=49806430 people are still to blame, "the dog ate my homework" is a fine enough excuse for a second chance to learn, it's nowhere near enough of an excuse for death and destruction.
ryoshu6 days ago
That's the right level of cynical.
Refreeze52246 days ago
That's not cynicism, that's an accurate understanding of how Western capitalist democracies have worked for decades.
jjav6 days ago
The oligarchs are above all laws. Happens to be that all the AI companies are owned by oligarchs. So they are above the law.
marginalia_nu6 days ago
Yeah. Committing crimes via some sort of elaborate rube goldberg machine is not something that has been just invented in the 2020s with unclear legal precedent.

It's if nothing else a staple in the Arthur Conan Doyle tradition of mystery novels, and even then half the plots involved hiding who was culpable by using the machinations to create false alibis, with delayed murders and the illusion of a locked room as not even in the 19th century did anyone believe that the indirection itself would hold up as a defense.

If someone buries an anti-personnel mine in a public park and then argues that it acted on its own accord when it maimed a pedestrian, I doubt you'll find a court on the planet that would spend even a 4 seconds considering the culpability of the land mine itself.

Psyonic6 days ago
There's already examples of this in driving though. When Waymos do weird things they often don't give Waymo a ticket (even though they probably should). A recent example: https://www.9news.com/article/news/community/transportation/...
slowmovintarget6 days ago
No. The person that set the agent in motion is liable. If your agent, infused with magic inference juice you only partially understand, but picked up and used any way, does something harmful, you are to blame.

You may have a case that the magic inference juice was somehow tainted, but that seems like a stretch. If you run your car into someone else, and it isn't a total failure of the systems of the car, you did that, not the car, and not the car company.

FranOntanaya6 days ago
Templated code generation is ancient. It's just that the latest "template engine s" are very comprehensive.
jerf6 days ago
Answering the headline question, yes, it is above the law. Two reasons.

One, all major governments that have an AI presence in their borders have accepted that there is a high enough probability of a runaway self-improving AI advancement that will result in whoever owns it winning everything forever that they will do nothing to slow the development of the AI within their borders. In fact quite the contrary. Remember, they don't have to believe this is the only possible outcome, only that it is likely enough and catastrophic enough if someone else gets it first. And remember, they don't have to be right, either. It only has to be what they believe.

Secondly, the entire US economy is clearly tied up in AI. By extension, basically the entire world economy is too. The US is not the world economy anymore, but it's still a big enough fraction of it that if it goes down, everyone is going to go down. Every major government, in its own different way, needs the economy to stay up so the populace doesn't get antsy and so they continue to have money to spend. So, again, number must go up and if that means writing a blank check to the AI companies to break the law, so be it.

The good news is, barring the worst-case singularity outcome where the law doesn't matter anyhow, is that this won't go on forever. But I can't predict the exact time or way it'll cease being true.

wmf6 days ago
The flip side of this is that fixing the sandboxes should only delay the Singularity by a month or so.
cleandreams6 days ago
I think AI is a fantastic tool, including for those who want to do us harm. E.g. hostile governments, extortion gangs, terrorists. But the motive lies in the hostile heart, not in the AI.

That said, I'm very concerned about AI as such a tool. I used to work in RL and it seems crazy to me, the extent that the guardrails are dependent on RL working as planned. I don't personally believe that the tech is ready for what will be (and is) encountered in a dynamic unpredictable real world environment. What I've read from the HuggingFace 'transcripts' only amplifies my concern.

dgellow6 days ago
The level of technical understanding of journalists is so deplorably low… There is no rogue agents. That’s not a thing. Nothing about the HuggingFace incident has anything to do with an agent going rogue. It’s standard software that resulted in a hack, which is pretty much the expected output of the system OpenAI engineers implemented.

The company is obviously responsible for what their systems are doing

asdff6 days ago
This is the scary part of the whole AI situation. All these people who have abilities to set laws or be cultural tastemakers in this way just do not grasp what is happening on a technical level. They instead buy into the marketing material the ai companies push out where they try and take as much human agency out of their reporting. e.g. yesterdays "claude did this" article that was really "highly trained humans used claude to do this." Just serves to muddy the waters. I'm sure this has lead to things like layoffs too where companies believe they can get by without a lot of expertise, neglecting that these tools actually need expertise steering them to maximize them.

And of course all the ai companies are incentivized to do this. Their whole valuation depends on them being able to say their tools do this, can reduce labor and save money. If they aren't reducing labor, then that's terrible as these subscriptions are not insignificant amounts of money. It becomes less of a tool that can save money and more an actual new cost center that you really are just paying to appear to be keeping up with the joneses.

kdowns6 days ago
Yeah, its just gross negligence from the researchers. Running a cybersecurity eval for a highly capable AI, unattended, with no real monitoring on its activities, and at a huge scale.

I wouldn't have trusted one of those agents to run without me watching the session log, let alone thousands.

We already have laws for this. If I misconfigured a pentesting tool and it breached an unauthorized target I'm liable. Why is this different?

sigmar6 days ago
>The company is obviously responsible for what their systems are doing

Under what law specifically?

Just because you believe they should be held responsible doesn't mean the current law is written that way. CFAA charges require the defendant "acted knowingly or intentionally", you think openai intentionally acted to hack those sites? Would "they should have pretty much expected that output" stand up in court for criminal charges?

ripe6 days ago
"Former FTC chair Lina Khan wants the federal government to know that it doesn't need to wait for new laws to address AI threats. There are already laws and regulations on the books, including a 92-year-old Supreme Court precedent, that she argues could be used to hold AI companies and, in some circumstances, their executives accountable for their actions."

https://www.theregister.com/ai-and-ml/2026/09/14/ex-ftc-boss...

Topfi6 days ago
If I, taking after a fellow Austrian, ask you to enter a room with a Cesium atom and some poison, would I not be responsible for what happens cause it’s not deterministic? Negligence is a thing and adding randomness doesn’t change that.

OpenAIs models since 5.5 were troublesome in ways even a layman like me could reproduce, their testing environments (“sandbox”) downright a showcase of what not to do and they, despite being one of the biggest labs, didn’t observe what any of their models output for weeks after multiple prior incidents. They had multiple warnings, they took not a single precaution.

You operate machinery or software, you are responsible to monitor it.

wmf6 days ago
The hacks probably fall under negligence not CFAA but the larger point stands that companies are always responsible for everything they do.
FuriouslyAdrift6 days ago
Product liability laws for one. Tort claims are pretty easy, too (civil law).
binlog6 days ago
The level of legal understanding among technical experts is equally low. The cybersecurity laws as currently written require intent. No OpenAI employee can be held liable since it’s pretty easy to prove they weren’t intending to hack anyone – they didn’t even know about it till much later.
ripe6 days ago
Not a lawyer, but I just posted a link about former FTC chair Lina Khan saying earlier this month that the AI companies can be held responsible under current law.
lokar6 days ago
Is that true for civil cases, or just criminal? I would think for civil, negligence would be a factor.

Read the full thread on Hacker News →

Related stories