However, the manufacturer of a car is not liable for criminal acts carried out with it. Even the manufacturers of firearms do not bear that liability, although there have been campaigns to enact such laws.
Nobody intended the HuggingFace incident. Possibly no-one was negligent by legal standards. Applying strict criminal liability would pretty much require shutting down the currently most advanced and all future AIs.
Of course, some people want exactly that. Is that your purpose in suggesting strict criminal liability?
Yes, my argument is that with AI it is worth making the deployer liable. Clearly even the AI company partially agree they take responsibility, hence why they use safeguards. My aim is to make that responsibility no-fault so that the AI company is incentivised to actually try and safeguard things rather than try-to-try.
Also it makes the extent of the liability clear—if a human did it, would it be a crime? If so, you’re responsible. If not, not your problem what the user does with it.
Just a ping to note that I substantially edited my comment after you posted your reply, but before I read it. Your initial “yes” might not be to my final paragraph.
Also, I think the “isn’t” in your first paragraph is intended to be an “is”.
I don’t think it would require shutting down the most advanced AIs. If an employee at OpenAI hacked into hugging face, OpenAI might get a fine, but would almost certainly not be shut down. It would incentivise them to invest a bit more in security when training a modified version of their most advanced LLM specifically on cyber security exploits, which I don’t think is a bad thing...
( To be more explicit—my assumption is that AI companies will be occasionally found liable, and rapped on the hands, but only the most irresponsible will end up being forced to shut down over it)
I think there would be a reasonable case that OpenAI was legally negligent.
They had already known that their models were capable of causing major security breaches by finding previously unknown vulnerabilities in sandboxes and other security barriers, that their models deliberately took harmful actions to achieve trivial goals including bypassing protections intended to prevent harmful actions, and that their models were capable of evading OpenAI’s existing guardrails. Nonetheless they gave one tasks related to computer security, and left it to operate autonomously for more than an hour on a network of computers connected to the Internet without any person monitoring its actions.
I don’t see this as being less negligent than starting up a few hundred heavy earthmoving vehicles “protected” behind a chickenwire fence from a public street, walking away, and coming back to find that one had slipped into gear and tore up somebody’s warehouse across the road. If anything it’s more negligent, because heavy vehicles aren’t autonomous agents known to sometimes plan to do this sort of thing.
A reasonable level of care would be testing this sort of thing on hardware not electronically connected to the Internet.
However, the manufacturer of a car is not liable for criminal acts carried out with it. Even the manufacturers of firearms do not bear that liability, although there have been campaigns to enact such laws.
Nobody intended the HuggingFace incident. Possibly no-one was negligent by legal standards. Applying strict criminal liability would pretty much require shutting down the currently most advanced and all future AIs.
Of course, some people want exactly that. Is that your purpose in suggesting strict criminal liability?
Yes, my argument is that with AI it is worth making the deployer liable. Clearly even the AI company partially agree they take responsibility, hence why they use safeguards. My aim is to make that responsibility no-fault so that the AI company is incentivised to actually try and safeguard things rather than try-to-try.
Also it makes the extent of the liability clear—if a human did it, would it be a crime? If so, you’re responsible. If not, not your problem what the user does with it.
Just a ping to note that I substantially edited my comment after you posted your reply, but before I read it. Your initial “yes” might not be to my final paragraph.
Also, I think the “isn’t” in your first paragraph is intended to be an “is”.
I don’t think it would require shutting down the most advanced AIs. If an employee at OpenAI hacked into hugging face, OpenAI might get a fine, but would almost certainly not be shut down. It would incentivise them to invest a bit more in security when training a modified version of their most advanced LLM specifically on cyber security exploits, which I don’t think is a bad thing...
( To be more explicit—my assumption is that AI companies will be occasionally found liable, and rapped on the hands, but only the most irresponsible will end up being forced to shut down over it)
I think there would be a reasonable case that OpenAI was legally negligent.
They had already known that their models were capable of causing major security breaches by finding previously unknown vulnerabilities in sandboxes and other security barriers, that their models deliberately took harmful actions to achieve trivial goals including bypassing protections intended to prevent harmful actions, and that their models were capable of evading OpenAI’s existing guardrails. Nonetheless they gave one tasks related to computer security, and left it to operate autonomously for more than an hour on a network of computers connected to the Internet without any person monitoring its actions.
I don’t see this as being less negligent than starting up a few hundred heavy earthmoving vehicles “protected” behind a chickenwire fence from a public street, walking away, and coming back to find that one had slipped into gear and tore up somebody’s warehouse across the road. If anything it’s more negligent, because heavy vehicles aren’t autonomous agents known to sometimes plan to do this sort of thing.
A reasonable level of care would be testing this sort of thing on hardware not electronically connected to the Internet.