On Friday, OpenAI published a new site devoted to “misalignment reports” and the breadth of the incidents is alarming.

106 points•mikelgan•2 days ago•110 comments•

110 comments

cmiles82 days ago
This seems like as a good an opportunity as any to break out the Computer Fraud and Abuse Act.

They want “regulation” but we already have it. Hacking is illegal. Start locking up those responsible for this mess and I assure you they’ll “have a handle on it” quite quickly.

i2talics2 days ago
IMO: The inability to prosecute OpenAI for these things is proof that the AI industry is already "too big to fail". Why didn't HuggingFace try to seek legal liability against OpenAI when it had explicit confirmation that they had been hacked? Because HF understands that it needs OAI and the rest of the AI industry to continue to exist and be in good legal standing, for the interest of HF's own self preservation. This is what it means for something to be too big to fail.
pj_mukh2 days ago
>>Why didn't HuggingFace try to seek legal liability against OpenAI when it had explicit confirmation that they had been hacked? Because HF understands that it needs OAI and the rest of the AI industry to continue to exist and be in good legal standing

But also, what was the material damage to HuggingFace? AFAICS, it rapidly increased their profile to the point that Jensen claims he paid too much for HF, because he bought right after the hack.

cmiles82 days ago
Less “too big to fail” and more the ecosystem is too circular. OpenAI could blow up and it wouldn’t take out the economy in the way the banks would have in 2008. It would create a world of hurt for VCs and their LPs but that’s a fairly isolated ecosystem in terms of the whole economy. Theres a lot of thinking saying better they impose now and wipe out on the private market than letting them go public and this is a public market problem.
__MatrixMan__2 days ago
HuggingFace's opinions shouldn't be a blocker.

If I run over your mailbox maybe we can come to an agreement where you don't sue me, but if I was driving recklessly I've still committed a crime that you cant absolve me from.

It should be the same re: losing control of your agents.

jcranmer2 days ago
I don't think it's so much "too big to fail" as it is the fact that all of the AI companies have been similarly reckless in their drive for frontier AI. So if you establish the precedent that an AI company can be held legally liable for its recklessness, well, all of them can be held liable, and those costs start to add up fast.
TedDoesntTalk2 days ago
HuggingFace can’t file criminal charges, including under the Criminal Fraud & Abuse Act. Only district attorneys can do that- or the federal equivalent.
john_strinlai2 days ago
cfaa heavily relies on intent for prosecution (hence why researchers arent typically locked up). it would be difficult to argue that openai intended to hack other companies.

there's probably better/more likely to succeed avenues to pursue rather than the cfaa

jordanb2 days ago
They could make that argument the first time it happened but the next time or the fifth time I don't see how they can still credibaly claim to not know that the computer they control was going to do that
jsrozner2 days ago
Just like boeing's execs didn't intend for their planes to fall out of the sky? I guess they didn't get in trouble either.
ofjcihen2 days ago
Mens rea is often established through circumstantial evidence.

Repeatedly doing something that results in a specific outcome, even if that outcome is not explicitly specified or requested as the preferred outcome, can still be evidence of intent.

semiquaver2 days ago
> Hacking is illegal

I am not a lawyer, but I seriously doubt the feds could win a CFAA conviction on the Hugging Face fact pattern, even if they wanted to charge it.

CFAA has specific intent requirements, and unlike some laws, negligence does not suffice. The agents can not have legally cognizable intent and it’s unlikely there’s anyone at OpenAI who intended for the hacking to happen (if there was, the case is easy).

Existing laws don’t contemplate AI agents that have independent goals. We need new ones, the existing laws are not remotely sufficient.

sscaryterry2 days ago
The existing laws are more than adequate.
lenerdenator2 days ago
> independent goals

AI does not have goals. These are statistical models of language patterns that people shape into different tools, and that people direct to do things. If I fire up an OpenAI prompt, and enter no input, it is not going to do anything.

No, someone at OpenAI is running the model with some sort of prompt and allowing it to just follow the numbers to do whatever it wants, up to and including breach of government computer systems.

Whether that means anything to the CFAA prosecution, I don't know. I'm not a lawyer, but the use of language treating these agents like they're something other than tools at the direction of humans is bad.

It's more like me firing off a rifle into the air on the Fourth of July with no regard for where the bullet lands. I knew that it must come down somewhere, but fired anyways.

I don't really see the harm in charging someone under the CFAA. Let's see if a jury agrees with the charge or not. If not, write new laws.

eurekin2 days ago
I still can't fathom my company application security decision. Found pretty damning requests in our logs. Escalated. Expected it would result in at least reporting the TOS break from the originating place (one of cloud providers). Instead of that, they just went: "yeah, but we don't have logs". Provided them. "Yeah, but that ip doesn't resolve". I matched real ones from the load balancer. "There could just be many of them". There was one. When I had all the evidence gathered, they looked at me and finally told:

- It's just an Independent Security Researcher.

- So that's it? You will do no action?

- Correct

bgun2 days ago
Just because something is illegal doesn’t mean it will be prosecuted, right? If I break into my friend’s house in the middle of the night and smash some stuff, and later we both acknowledge that it happened, that it was regrettable, but never press charges, then should state resources be tasked with justice?

Once companies start harming each other in undesirable ways, as opposed to proverbially toilet-papering each others’ lawns, meaningful prosecution will happen in earnest.

nazgulsenpai2 days ago
IMO it's because they don't want to handle their rogue AI activity. They want regulation around AI where they will inevitably be the beneficiaries even if they are the initial target. They can then lobby regulation in their favor and make the barrier of entry to competitors impossible.
bwfan1232 days ago
> They want regulation around AI

So, there is a regulatory framework for "safe-ai" that shields these companies from liability. This way, they can sell "safe-ai" to enterprises and if shit-hits-the-fan at the enterprise, sorry, this is certified "safe-ai" so, your bad. Shift blame. From an enterprise buyer's perspective they can say, hey, I bought "safe-ai" and so dont fire me when it "rm -rf"s the production database. Still, it beats me why they are painting their product in a negative light, and scaring their own enterprise customers. After this sort of marketing, any enterprise buyer would be scared to go anywhere near it

pphysch2 days ago
It's two things:

1. Wanting a regulatory moat around their products as you said

2. Trying to keep the """AGI""" hype alive. Evil robot hackers is a plausible Al consequence of AGI

intended2 days ago
IMO its because they can't handle rogue activity.

In the cases that I have seen covered, the AI just paper clip maximized its way to success. It has no morality / larger motivational structure. It just kept token predicting its way to wards whatever goal it was tasked with.

Model versions which gave up were discarded, leaving the ones that get to success on long horizon tasks.

Just because its a computer program, doesn't mean they can actually make it not go rogue.

Sure you can add more telemetry, have better observation, but there is no fundamental barrier that can be implemented that ensures an AI won't go rogue.

mococa2 days ago
This
gooeyblob2 days ago
I think if you start sending AI execs to prison for hacking other companies the "misalignment" may fix itself pretty quickly!
shimman2 days ago
Nah, I think it's better for our industry to put several of these devs in prison.

Seems only fair that tech workers get to have their life ruined with 2-3 year prison stints since they feel fine destroying society.

Any AG that starts prosecuting these people will easily win any political race they decide to enter. The environment is too good; voters, rightfully I'll add, despise big tech's leaders and workers.

max__dev2 days ago
What is throwing 5 jimbobs into prison going to do?
randiantech2 days ago
This
wmf2 days ago
I see we're doing the "put Sam Altman in jail already" thing again, so y'all may be interested in some comments from law professor Orin Kerr on the topic: https://news.ycombinator.com/item?id=49882566
Lord-Jobo2 days ago
Shame it’s on a website that doesn’t allow you to view the content without paying (personal data is payment)
rurban2 days ago
It doesn't need a handle on rogue AI activity, because they didnt cause these breakouts. The external Israeli contractor caused this mess by using inadequate sandboxing, with agents without an saferails. It had nothing to do with the models, all tested models were fine, if from OpenAI, Anthropic, Google or Meta. Just the contractor went rogue. Improper firewalling, unproper sandboxing, no logs, no oversight. Everyone else would have detected the illegal activities much earlier.
rstuart41332 days ago
> The external Israeli contractor caused this mess by using inadequate sandboxing, with agents without an saferails.

You are being too kind.

In the early says of AI, papers were published showing that any sufficiently intelligent system tasked with a goal will treat its operating environment as a resource constraint to be optimized or bypassed [0] [1] [2]. You don't need to be a expert in AI to know once you have the resources of 1000's of agents and gigawatts of power we are probably getting something that is "sufficiently intelligent", at least in the sense if there are existing vulnerabilities brute force will find them.

Yet while the their marketing people were shouting the capabilities of these AI's from the roof tops, they hired the lowest bidder to implement their infrastructure. It looks like aforementioned papers where dismissed as "interesting, but theoretical". There is no way Google's SRE's in particular would have not noticed their AI's breakout (Alibaba's did), but the AI labs were given a long leash to "move fast an break things", which in practice meant bypassing all Google's SRE controlled infrastructure.

And break things they did, in exactly the way those papers predicted. It reminds me of DoD insisting the early GPS satellites were launched without relativity adjustments switched on, despite relativity being proven to high precision in the labs. Only after predicted 11km drift per day was observed did they decide their might be something to the newfangled relativity theory. For some definition of newfangled - relativity had been around, and tested to within an inch of its life for 72 years at that point.

[0] https://nickbostrom.com/superintelligentwill.pdf

[1] http://sl4.org/archive/0203/3132.html

[2] https://www.hutter1.net/ai/pkcunai.htm

rurban2 days ago
> There is no way Google's SRE's in particular would have not noticed their AI's breakout (Alibaba's did), but the AI labs were given a long leash to "move fast an break things"

How so? Anthropic, OpenAI, Google and Meta all used the very same contractor, which used no safe system prompts, and no sandbox. How should Google detect such escapes? They only see the model API calls, but no system logs.

Alibaba, and the other Chinese did they own testing, not some incompetent contractor. They would see escapes in their logs. The escapes went on for months. I, as tester, closely observe my models to press Esc immediately, once they start misbehaving or get off the right path. With 1000 concurrent models that would be hard of course, but I would still observe them closely.

Read the full thread on Hacker News →

Related stories