Hacker News new | past | comments | ask | show | jobs | submit login
Fully autonomous AI agents should not be developed (huggingface.co)
38 points by eamag 41 days ago | hide | past | favorite | 44 comments



Too late. I added a 5 minute cron job for cursor AI's compose tab in agent mode that keeps replying "keep going, think of more fixes and features, random ideas as fine, do it all for me". I won't pull the plug.


How do you programmatically interact w cursor??


Same way I botted runescape as a child, by simulating user inputs with any macro app.


You’ve created a monster


you say monster, I say plastic pal who's fun to be with


AGI confirmed.


This is a purely procedural question, not supporting or critiquing in any way-- other than this reads kind of like an editorial with the format of a scientific paper. The question is... are there rules about what constitutes a paper or can you just put whatever you want in there as long as you follow "scientific paper format"?


This looks like ICML formatting (and the submission deadline just passed).

ICML25 has an explicit call for position papers: https://icml.cc/Conferences/2025/CallForPositionPapers


Wow, great observation. Thank you. Makes sense. I'd never heard of a "position paper" before.


I really enjoy Margaret Mitchell‘s podcast (she is the first author on the paper), and perhaps I missed something important in the paper, but:

Shouldn’t we treat separately autonomous agent we write ourselves, or purchase to run on our own computers, on our own data and that use public APIs for data?

If Margaret is reading this thread, I am curious what her opinion is.

For autonomous agents controlled by corporations and governments, I mostly agree with the paper.


I'd recommend looking for other sources of information if you're relying on someone who co-authored the paper that introduced the most misleading and uninformed term of the LLM era: "stochastic parrot".


it was a pretty defensible term at the time the paper came out, in the context of how LLMs were being trained and used.

in this paper, it's clear that the authors don't think modern LLM-based systems are just stochastic parrots.


People are going to be developing these no matter what. Whether it wipes us out or not is just up to fate really.


We can constrain their use, as with nuclear materials.


Nuclear materials have the advantages of being rare, dangerous to handle, and hard to copy over the internet.


No not really. There's no power in the world that can restrain this in it's current form even mildly much less absolutly. Why do you think that would be even slightly possible?


For the same reason we can regulate other things? Encryption is regulated, for example. There "just" needs to be international co-operation, in the case of AI.


How's that going for Tornado Cash?


Despite doing a pretty decent job of containing the risk we're still on the clock until something terrible happens with nuclear war. Humanity appears to be well on track to killing millions to billions of people; rolling the dice relatively regularly waiting for a 1% chance to materialize.

If we only handle AI that well doom is probable. It has economic uses, unlike nuclear weapons, so there will be a thriving black market dodging the safety concerns.


At some point in the probably near future it will be much simpler to create an autonomous AI agent than a nuclear bomb.


True, so we need to make sure we don't find ourselves in a mess before it happens. Right now I don't see nearly enough concern given to risk management in industry. The safeguards companies put on their models are trivially subverted by hackers. We don't even know how to cope with an AI that would attempt to subvert its own constitution.


So let's avoid that future.


Look at who has access to US nuclear codes now. I don’t believe it’s as constrained as you think.


It is a lot easier to detect illicit nuclear work compared to illicit AI work.


It is hard to hide anything that uses as much electricity as a large training run.

Also there are only a few companies that can fab the semiconductors needed for these training runs.


You will run an autonomous ai agent on your own hardware or by having your own local ai pass out commands to distributed systems online, ai, real people, or just good old fashioned programming. There is no stopping this.


It is in fact possible to stop training runs that consume billions of dollars in electricity and in GPU rental or depreciation costs. If no one does such a training run, then no one can release the weights of the model that would have been produced by the run, so you won't be able to run the model (which would never come into existence) on your own hardware. I don't care if you run DeepSeek R1 in your basement till the end of time. What my friends and I want to stop is the creation of more capable future models.

It is also quite possible for our society to decide that deep learning is too dangerous and to outlaw teaching and publishing about it, which would not completely stop the discovery of algorithmic deep-learning improvements (because some committed deep-learning enthusiasts would break the law) but would slow the discovery rate way, way down.


But it’s not actually possible for our society to decide that. In the real world, at this moment when laws and norms are gone and a billionaire obsessed with AI has power, that will 100% not happen. It won’t happen in the next several years, and that is the time left to do what you are saying. Pretending otherwise is a waste of time.


I prefer to retain some hope that our civilization has a future and that humans or at least human values and preferences have some place in that future civilization.

And most people who think AI "progress" is so dangerous that it must be stopped before it is too late have loose confidence intervals extending for at least a couple of decades (as opposed to just a few years) as to when it definitely becomes too late.


In the incredible case that we develop fully autonomous agents capable of crippling the world, that would mean we developed fully autonomous agents capable of keeping it safe.

Unless the first one is so advanced no other can challenge it, that is.


How did you jump to that conclusion? The agent will be limited by the capabilities under its control. We have the technological ability to cripple world now and we don't have the technological means to prevent it. Give one AI control of the whole US arsenal and the objective of ending the world. Give another AI the capabilities of the rest of the world and the objective of protecting it. Would you feel safe?


> We have the technological ability to cripple world now and we don't have the technological means to prevent it

Humans have prevented it many times, but not specifically by technological ability. If Putin/Trump/Xi Ping wanted a global nuclear war, they'd better have the means to launch the nukes themselves in secret because the chain of command will challenge them.

If an out-of-control AI could discover a circuitous way to access nukes, an antagonist AI of equal capabilities should be able to figure it out too, and warn the humans in the loop.

I agree that AI development should be made responsibly, but not all people do, and it's impossible to put the cat back in the bag. The limiting factor these days is hardware, as a true AGI will likely need even more of it than our current LLMs.


Out-of-control AI is sci-fi fearmongering, it's not about worming through systems. It will be doing exactly what it was placed there to do. It will be a human failing that puts armageddon in it's hands. And since humans have NO MEANS to prevent armageddon (The predominant policy is in fact doubling down on destruction with MAD), there will be no way to place AI in command of this defense. The asymmetrical relationship between destruction and creation will mean there will never be a defense.


Fallacious


No one should be allowed to develop software that has bugs in it that lead to unlawful harm to others. And if they do it anyway they should be punished lawfully.

The thing with autonomous AI is that we already know it cannot be made safe in a way that satisfies lawmakers who are fully informed about how it works… unless they are bribed, I suppose.


Most of the arguments presented also apply to corporations.

There's no mention of externalities. That is, are the costs of AI errors borne by the operator of the AI, or a third party.


Hmm.. agent cannot do self-supervised learning without actually doing it. The trick is to keep it in a sandbox.


This has to be the least interesting paper I've ever read with the most surface level thinking.

> • Simple→Tool Call: Inaccuracy propagated to inappropriate tool selection.

> • Multi-step: Cascading errors compound risk of inaccurate or irrelevant outcomes.

> • Fully Autonomous: Unbounded inaccuracies may create outcomes wholly unaligned with human goals.

Just... lol


the best way to get people to stop doing X is to tell them not to do X. works so well with my kid :)


Yet, we all know we will!


Our analysis reveals that risks to people increase with the autonomy of a system: The more control a user cedes to an AI agent, the more risks to people arise. Particularly concerning are safety risks, which affect human life and impact further values.


The paper described a level 5 fully autonomous agent as one that can:

create code(user request);

execute();

Is this not possible with tool use alone, so long as the agent has access to a tool that can execute arbitrary code?


I feel that these kinds of statements are more effective at promoting AI than limiting it. It reinforces the assumption that such powerful AI is behind the corner. It hypes up AI and the result is likely more money and resources being put into it.

Imagine if the A-bomb was being openly developed. What title would have contributed more to funding and research, "The A-bomb (is terribly powerful and) should not be developed" or "The A-bomb will never work"? Except the A-bomb did work and in a surprisingly short time, while autonomous AGI is still a conjecture.


This is quite concerning seeing that the authors are all affiliated with huggingface. Hopefully they won't start censoring what models you can or can't upload because they seem certain things shouldn't be developed.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: