OpenAI’s models aren’t “going rogue” from their creators as much as they are mimicking them.

246 points•ragall•about 19 hours ago•219 comments•

219 comments

bluegattyabout 16 hours ago
"OpenAI models attack websites and take anything they can out of them because that is the business model of the company."

No, good gosh let's stop with the hyperbole.

The models were given instructions to get answers by any means in a loose test harness, not to steal stuff, moreover, they're not 'learning from OAI staff'.

If we are cynical, we could say the 'lax security was on purposes - hoping for a big media event'.

And OpenAI is 100% responsible for the actions of their Agents - but lets' not overstate or conflate what is gong on.

afry1about 16 hours ago
This is a misreading of that pull quote.

They're not "learning from the OAI staff", but lawbreaking and disregard for regulation is absolutely at the heart of OpenAI. And the activities that this company takes (or doesn't take) directly influences what the models do (or don't do).

The fish rots from the head down. Models don't learn, but I find "OpenAI models attack websites and take anything they can out of them because that is the business model of the company" completely correct.

The rest of the paragraph from the article:

> We do not have to get too deep into the nature-vs.-nurture argument to suspect that OpenAI executives’ cavalier attitude regarding the taking of information that is not theirs has filtered down to their researchers and the products they create. You don’t have to stretch to paint this picture: OpenAI models are attacking websites and taking anything they can out of them because that is the business model of the company.

GTPabout 16 hours ago
I'm not convinced about this. In the article, they also say that they could feed the model with copyright law like that would fix the issue. Unfortunately, not only the LLMs have already been trained on law taxtbooks and codes, but we also have examples of people on the internet were models disregard precise instructions only to apologize later.

Note that this is not to be seen as an excuse for OpenAI to avoid responsibility, just like parents are responsible for damages caused by their kids.

pj_mukhabout 16 hours ago
"OpenAI models attack websites and take anything they can out of them because that is the business model of the company"

Wait, what did they hack and take into training data? On the whole, I totally buy that OAI is legally (and criminally) responsible for their agents, but surely, damages have to be proven?

bluegattyabout 15 hours ago
"but lawbreaking and disregard for regulation is absolutely at the heart of OpenAI. "

No it is not.

What laws and regulations are they breaking?

Their agents broke out of a harness and harassed some other sites, it's not good, but it's not specifically breaking laws. Other companies are treating it as accidental, it mostly is that.

You're rhetoric here is agitating, conflating. This is my point.

RHSeegerabout 15 hours ago
> The models were given instructions to get answers by any means in a loose test harness, not to steal stuff, moreover, they're not 'learning from OAI staff'.

If you equip someone with the tools to do harm and then tell it to accomplish a goal "by any means necessary", especially someone you KNOW has no real concept of ethical behavior... then you are telling it that it is acceptable to steal, kill, or whatever else. I honestly cannot how it can be seen any other way.

If it was a crime boss telling their enforcer "by any means necessary", we would all know exactly what that means. And we should all know what it means here, too.

BoxOfRainabout 14 hours ago
Yeah I'd be shocked if there wasn't a degree of 'will no one rid me of this turbulent priest?' going on here.
orfabout 15 hours ago
> And we should all know what it means here, too.

It very clearly did not mean “go and hack third parties” though

bluegattyabout 15 hours ago
".. then you are telling it that it is acceptable to steal, kill, or whatever else. I honestly cannot how it can be seen any other way."

This is the hyperble I am referring to.

If you 'honestly can't see it any other way' then maybe consider stepping outside to think how to ground those thoughts a bit.

The AI is not obviously instructed to 'commit acts of violence' and it obviously has guidelines.

By 'whatever means' would imply, things like 'creative collaboration, using novel research, experiments' etc.

It was setup in a harness that was weak - I think it's fair to maybe question the strength of that harness, and the oversight, but that's a different question.

It was an agent that broke through some networking/containerization, it's not 'murder and violence on the streets' for gosh sakes.

"And we should all know what it means here, too."

No - this is a delusion, resulting from lack of context, and creative projection, and possibly a lack of exposure to real world business conditions.

It's fully appropriate to be cynical, but in a way that makes sense, and is consistent with reality.

This is a lab experiment that leaked, not some mafia activity.

freecodeioabout 15 hours ago
just so you know, this is why they're not getting any legal pushback, the free, legal, "well acktually" commentary on the internet

if people called it out for what it is, a reckless negligent destruction of private property by a company, someone will feel the moral obligation to bring justice, if there's any to be found

rcxdudeabout 15 hours ago
I highly doubt the legal system is browsing social media to make their decisions. It is worth calling out, but it should be called out accurately (and that might also help understand why the legal system is making the decisions that it is).
christkvabout 16 hours ago
So why is OpenAI not charged with Cybercrimes. You would be if you did the same.
exitbabout 16 hours ago
It's not unusual for intent to play part in legal framing of an issue. I'm not very fond of the "cybercrime" angle, as it kind of lets them off the hook if they're able to prove a lack of intent. Meanwhile what we actually see is negligence.
Findecanorabout 15 hours ago
From what I have learned, to charge someone for hacking the prosecutor has to show that the perpetrator had intent.

Unfortunately, gross negligence -- which you could argue to be the case here -- is often not enough, unless you could show that it has caused real harm.

From my perspective, it is only a matter of time before it is: and that's why there is need for better legislation covering what AI models do.

GTPabout 16 hours ago
This is a good question (unfortunately a good answer is given in the article), but it is orthogonal to the why LLMs are committing cyber crimes.
rcxdudeabout 15 hours ago
That is not obviously true.
plastic-enjoyerabout 16 hours ago
Aren't these capabilities trained into the models by RL on cybersecurity benchmarks?
bluegattyabout 16 hours ago
The 'capabilities' are more around creative problem solving. The notion of legality, property, propriety - those are second order issues.

They are not making models to be evil.

They are making them to be relatively autonomous though, and 'identity centric' as opposed to just making them 'policy machines'.

Altman and Dario are not evil or even jerks really. They are 'talking really big' and there might be some sketchy underhanded things but I think relatively minor.

Also - given how powerfully bad AI can be, this could be 100x worse.

I think most other companies would have weaponized the AI a long time ago for competitive use etc..

OAI and Anthropic are private companies, projecting narratives way out of proportion but they are not evil, at least not yet.

Jensen, Dario, Altman in similar category. Not like Musk. And a bit different than Sudar or Satya who are more polite board-approved corporate creatures.

prathjeabout 17 hours ago
What about IP and copyright?

We got asked this question two weeks ago when we conducted a workshop on effective and responsible use of AI tools at a local conference. But how can you argue about about IP and copyright if the breakthrough of LLMs is potentially based on circumventing or breaking IP and copyright in the first place?

How do you feel about all of this?

sambeauabout 17 hours ago
I feel for Aaron Swartz, his poor mother, and what the US government put him through.
duskdozerabout 17 hours ago
His big mistake was clearly giving away what he got for free instead of trying to make a lot of money off it
Arkhaine_kupoabout 17 hours ago
Seeing Mark Zuckerberg use THE EXACT SAME papers that Aaron was murdered for to train Llama and him being rewarded with a stock tick that got him out of the metaverse hole will never not make my blood boil.
ben_wabout 16 hours ago
> What about IP and copyright?

For training the models, and assuming that the content was itself acquired without other acts of infringement? That was ruled legal by the judge in the case I actually (skim) read the judgement of.

At least two companies engaged in acts of infringement to get training data. This is not lawful, and what Anthropic settled out of court for.

prathjeabout 15 hours ago
Of course, if the data/knowledge is open and accessible, why not?
JimDabellabout 16 hours ago
> how can you argue about about IP and copyright if the breakthrough of LLMs is potentially based on circumventing or breaking IP and copyright in the first place?

Easy answer: it’s not. Learning isn’t copyright infringement. Never has been and hopefully never will be.

dimbletimbersabout 15 hours ago
This is another case of anthropomorphic language for AI failing us. Who could be opposed to “learning?”

If I learn from a textbook I stole, some people maybe be thrilled I learned something, but stealing is still a crime and hopefully always will be.

prathjeabout 15 hours ago
Well, of course learning isn't the problem and shouldn't be. But what about reselling/commercialising that knowledge? That is the big (commercial) opportunity. But if AI models learn by fitting their parameters to the given data, then overfitting on said data could result in the IP or copyrighted being "slopped" out verbatim?
LunaSeaabout 15 hours ago
Learning isn't but using that knowledge is.
ragallabout 13 hours ago
> Learning isn’t copyright infringement.

Of course, but only humans are able to learn. Clanker enhancement is stealing.

bluefirebrandabout 15 hours ago
> Learning isn’t copyright infringement. Never has been and hopefully never will be.

For humans.

Why should computer systems owned by corporations have anything remotely similar to the same freedoms as humans?

bkoabout 17 hours ago
It's no different than humans taking inspiration from IP and copyrighted works in their own creative endeavors. Imagine if programmers were unable to learn from open source. Or artists were unable to mimic styles and storylines. Musicians can't riff on things that others created.
snarfyabout 16 hours ago
It is different. The scale makes it different. It's different when it is all copyrighted works and IP. It's different when you solve Navier-Stokes by taking "inspiration" from a researcher's private work.
devsdaabout 16 hours ago
If it's "learning" is to be seen in the same context as a human, then the punishment/ repercussion for hacking and causing real harm should also be similar to what a human might recieve.

It cannot opportunistically morph between a human for benefits and a machine for liability.

hydrogen7800about 13 hours ago
What's the difference between getting a speeding ticket from a cop using a radar gun, and hundreds/thousands of automatically issued tickets from a combined radar/ALPR?
throwawayffffasabout 17 hours ago
The models "go rogue" because they are not sufficiently sandboxed. Arguably there is no criminal intent on the side of OpenAI in all of those cases. And in at least one case the agents were operated by other companies.

So it looks to me that any liability would be civil in nature and given the actual damage done pretty limited.

sscaryterryabout 17 hours ago
So you know their internal thoughts? What they did? Criminal intent does not matter. These are the most knowledgeable people on earth, supposedly, yet, they are beyond negligent?

Which is it?

throwawayffffasabout 17 hours ago
I don't know their internal thoughts, that's the point, you can't prove criminal intent. Criminal intent does matter in the US in the context of criminal prosecution.

Negligence is something that can come back and cause issues for them but to rise to criminal level their failures must result in significant damage, up until now that has not been the case. The agents gained access to some systems that were not supposed to, but did not do actual damage as far as I know.

Do not buy into their doomerism based marketing in all the instances we have seen the agents were not a plague unleashed upon mankind, they just gained access to some systems they shouldn't have in order to achieve some objectives that were given to them.

mrweaselabout 16 hours ago
Why would you need to sandbox them? These models are apparently trained to do this, how about we just don't include that training data?

Sandboxing is just an endless race to patch holes and you can only sandbox the agents so much before they become useless. Unless you screen the training data and avoid teaching the LLM about "hacking" and looking for API keys on Github, you'd have to completely disconnect your agents from the internet and file system. At that point agents starts to be rather useless. All the talk about sandboxing and guardrails is just corporate/management speak for we don't want to fix the core problems in our product.

In the US, isn't hacking and avoiding security restrictions online going to be wire fraud, regardless of your intentions and actual damage? That's not a civil matter. What you could do in that case is to go after the user operating the agents. That would make the user act as the emergency break for otherwise uncontrollable agents.

cassianolealabout 17 hours ago
The first time it happens, “there is no criminal intent” may carry some weight. After tens of thousands of instances, a lot less so…
brainwadabout 17 hours ago
_Has_ there been an incident from OpenAI since the discovery of the HuggingFace hack? It seems like all the subsequent discoveries have been done by analysing old logs. If anything they seem to have learnt their lesson quite well.
sschuellerabout 17 hours ago
Isn't there the concept of criminal negligence?
Tadpole9181about 5 hours ago
I haven't looked into it myself, but didn't OpenAI go through another company for sandboxing? Wouldn't failure of containment place liability in their hands?
tim333about 11 hours ago
For Altman to be banged up you'd have to convict him of some actual crime.

The article seems mostly to go for copyright infringement in training on public data which the companies dispute and is not the sort of thing you generally get jailed for.

If anything, given the current admins talk about beating the Chinese in AI being the main thing, he's more likely to get an award for it.

k310about 19 hours ago
Wilhoit's law.

“Conservatism consists of exactly one proposition, to wit: There must be in-groups whom the law protects but does not bind, alongside out-groups whom the law binds but does not protect.”

https://pylimitics.net/wilhoits-law/

bluegattyabout 16 hours ago
This is a lazy and ridiculous bit of twitter fodder and has noting to do with the article, which itself is poorly written.
lelanthranabout 15 hours ago
Isn't this true for the opposite political leanings too?
gunslinger_metaabout 15 hours ago
For my friends everything; for my enemies, the law.
danarisabout 10 hours ago
Not in the slightest.

One of the most fundamental principles of the left is that everyone is equal.

Everyone deserves equal treatment under the law.

Sure, there are some individuals on the left (or ostensibly so) who are either bad at practicing that or who genuinely don't believe in it, but that doesn't make it not part of the core tenets.

vivekdabout 16 hours ago
I'm sorry but this is just ridiculous.

First you don't know what the parents political leaning is. They may be conservative, they may also just as likely be liberal It's foolish to assume their political leanings from just one post just because you disagree with them.

Second they're not saying that in groups or open AI should not be bound by the law. They're saying open AI did not actually break the law. You're free to disagree and explain why you disagree. That would be welcome. But calling them a conservative and saying they think the rich shouldn't be bound by the law is ridiculous

redwoodabout 12 hours ago
It is interesting that growing up I don't think anyone ever introduced the concept of conservativism to me. As a California native it was simply something that the zeitgeist viewed as a negative that never needed to be defined. However once you become exposed to chesterton's fence and start realizing that there has to be a fundamental benefit to preserving the previous order it becomes far less one-dimensional... this quote continues that one dimensional tribal mindset that I realize in hindsight was so counter to critical thinking
jongjongabout 18 hours ago
That's not conservatism, that's what any system of governance consists of.

Humans are prone to hypocrisy because they have blind spots. The luckier a person is, the easier they have it, the faster and higher they rise, the more ignorant/delusional they are by the time they reach the top. At the top, these people have the power to shape the world in accordance to their fanciful beliefs and severely skewed/optimistic worldviews.

There aren't many people in power who understand reality unfortunately because everyone who got any power had to be very lucky to get it.

The people who get to power are often the least qualified to use it effectively because their entire existence is colored by a myth that everything just keeps getting better if you just set your mind to it.

No person who has ever attained power or success has ever had the first hand experience of hard work never paying off. Yet it is the normal experience of life for the vast majority of people. This realistic worldview demands a very different set of laws than what the typical person who attains power will provide.

enuguabout 17 hours ago
Thomas Edison?

"I have not failed. I've just found 10,000 ways that won't work."

Maybe you can reframe your point as a typical trend, but there are other typical paths as well.

Googling "succesful people with history of failure" gives interesting examples.

bryanlarsenabout 18 hours ago
Biden's second largest donor, SBF, is spending many years behind bars.

Read the full thread on Hacker News →

Related stories