Thank you! That sentence also jumped out to me as the solution: Apply civil and criminal liability to the creator and/or operator of these agents using the laws we already have. "Escaped containment and hacked another company's database" = Individuals who created the models and those who set them to work are charged and put on trial for the hacking. Just like if a human had done it by hand. Someone must be liable, and it should not be the model- because the model is not a person.
If this is done systematically (i.e. in jurisdictions across the world) I believe the problems will be solved in short order; we won't have to mandate what sort of training is "allowed" or not, "safe" or not. The creators and users will sort these themselves, as their incentives will be properly aligned (i.e. they are liable for what the agent does). I am confident that this approach would see a great blooming of very trustworthy AI models.
There was a sow in Falaise in northern France that killed a kid in 1386. The town dressed the pig in a bonnet and hanged it after sentencing the pig itself and not its owner
I mean I think there’s a similar level of judgement required.
Was the owner negligent in controlling their pig/dog/AI?
Was anyone else negligent along the way?
For example if the pig was just a normal pig, the owner cared for them normally, and there was a freak accident where the pig escaped and happened to kill a kid? Obviously nobody at fault.
If you have a dog with a history of violence and let it walk around off-leash with you around town, and it kills a kid? Absolutely the dog owner was negligent and should be charged.
Did you buy an AI sold to you as secure and the provider implies that it’s in a sandbox? Provider is on the hook for the damage.
Firstly it's very difficult to press criminal charges when the victim is uninterested. It's not clear that HuggingFace would want criminal charges against OpenAI, especially to set a precedent that could easily be used against HuggingFace in the future.
Secondly you'd have to convince a jury either that OAI intended to hack the targets, or that they were criminally negligent. Intent would obviously not be provable since they likely didn't, in reality, intend for it to happen. Regarding negligence, OAI's attorney would argue that the agent was in a sandbox, that industry-standard security protocols were followed, etc. It would not be anywhere near as much of a slam dunk case as you're imagining. It would be similar, for example, to an assault case where someone's dog broke off of a standard leash and attacked someone.
I can't say it enough how angry it makes me that a kid i knew in high school who anonymously reported a vulnerability on his college network was hunted down and given federal charges, yet not one single person at OAI or else will see even the threat of consequences for deliberate infiltration of random networks.
Copyright immunity was one thing, annoying yes but naturally a civil matter, this shit is a different level
Agree! My only concern is - is the judicial system fast enough, and resilient enough? Or will these creators get "off the hook" by using their agents to find loopholes, sway public opinion or even convince Trump to grant them immunity?
Still, I have no idea why OpenAI & co. are not being sued for these hacks.
My opinion and based on my observations: The recent track record with courts, prosecutors, and lawmakers keeping social media companies accountable is a relevant case and does not encourage me. It has taken a long time (decade +) for society to recognize the harms and finally start holding some to (partial) account. If you want an older precedent, the tobacco companies were able to dodge liability for multiple decades after knowing the harms from use of their products.
So, your question is spot on- I think the speed will be an issue. On resilience, I am more optimistic.
The old quote, "The wheels of justice turn slowly, but they grind very fine" (as well as I can remember it) seems to apply. I expect lawsuits to start landing in the coming years.
If this is done systematically (i.e. in jurisdictions across the world) I believe the problems will be solved in short order; we won't have to mandate what sort of training is "allowed" or not, "safe" or not. The creators and users will sort these themselves, as their incentives will be properly aligned (i.e. they are liable for what the agent does). I am confident that this approach would see a great blooming of very trustworthy AI models.