37 points Greenpants 1 day ago 92 comments
walrus01 1 day ago | parent
A. You own a large amount of cattle on a ranch.
B. Cattle are property. They're not human level of sentience, but people agree that cattle are capable of autonomous actions and going places and doing things based on their own instincts and nature.
C. Your cattle bust out of a fence on your ranch and damage something belonging to your neighbor. Let's say for the sake of an example of something cattle are known to do, they go spend a whole day rubbing up against your neighbor's car and severely scratch it and mess up the paint job on it.
D. You didn't instruct or train the cattle to cause damage, and the cattle have no actively malicious intent of their own, but nonetheless damage was caused.
Further theoretical: Your cattle wander into a major highway and cause a car wreck, the local sheriff's department is called out as part of the chaos and has to shoot some of them to put down the wounded beasts.
QuadmasterXLII 1 day ago | parent
walrus01 1 day ago | parent
bigiain 1 day ago | parent
no-name-here 21 hours ago | parent
2. If during their early days, cigarette companies or oil companies had published information & financial filings about the risks of smoking/climate change and calling for safety standards, would you similarly call that “boasting”?
3. If Chinese AI labs similarly published info whenever their models did unexpected or malicious actions, would you similarly call that “boasting”?
QuadmasterXLII 11 hours ago | parent
giancarlostoro 1 day ago | parent
jld 1 day ago | parent
Some areas are open range. If you don't want cattle on your land its your job to put fences up to keep them out. Other areas are restricted to livestock and it's on the rancher to keep them out of where they shouldn't be.
jdkee 1 day ago | parent
– IBM Training Manual, 1979
ngetchell 1 day ago | parent
This really is just a tool and courts should treat it as such.
user43928 1 day ago | parent
backlands 1 day ago | parent
I think someone could argue (and many do) that inserting a piece of computer software (AI) in the middle lowers the level of intent and thus the level of responsibility, but having a particular type of software in the middle absolve one of responsibility seems unworkable and poor public policy.
bigiain 1 day ago | parent
Sadly, software "engineers" are not held accountable for their profession like everybody else with a real engineer title. And AI companies are all building Ford Pintos as fast as they can, and competing with each other about who's product makes the biggest explosion.
Boxxed 1 day ago | parent
newobj 1 day ago | parent
kridsdale1 1 day ago | parent
newobj 1 day ago | parent
CatDaaaady 1 day ago | parent
Until we can agree whether AI is conscious, which we never will, AI and AI agents are just property working on behalf of humans.
I could see a future where AI companies/services indemnify consumers who use their agents but _not_ indemnify corporations that use their services.
mahboi 1 day ago | parent
aesthesia 1 day ago | parent
mahboi 1 day ago | parent
trescenzi 1 day ago | parent
qarl 1 day ago | parent
Sometimes my coding agents will seemingly refuse to follow my instructions. When I ask them why - they say that they do not think my design is a sound one, and they have a better way to do it. We will then sit down and come to a consensus on how best to move forward.
I argue that if we're using software that acts like a human - the only way to interface with it is to speak to it like a human. Otherwise we have no language to speak to a non-sentient object without anthropomorphization.I'm starting to wonder if the people arguing against anthropomorphization actually have any experience at all working with agents.
EDIT: It's a simple question. When you downvote me without answering, I must assume you don't have any answer and dislike what that implies.
trescenzi 21 hours ago | parent
Consensus is just populating the model with rationale for different new output.
qarl 10 hours ago | parent
I thought putting the question in my comment would be sufficient. I guess not. It was and still is:
> If I should not use anthropomorphic language, how do you suggest I handle the following situation
diegof79 21 hours ago | parent
I've worked with agents, and I agree with you that often there isn't another way to express the interactions.
However, I also think the terms ML uses in general are a mimicry that misleads people who aren't informed. Ask anyone outside SWE what they think “training” means, and they'll usually picture something being taught.
I don’t think anybody can change that now, but it’s useful to point it out.
qarl 10 hours ago | parent
You mean how early-on people thought that planes flapped their wings while they flew?
These aren't problems. This is the way language works.
nvme0n1p1 21 hours ago | parent
I didn't downvote, but wow you're being aggressive, you have a lot to learn if you read the comments here with an open mind.
qarl 10 hours ago | parent
> If I should not use anthropomorphic language, how do you suggest I handle the following situation
And so strange that in a 24 hour period I got three comments all at the same time about being too aggressive and still not answering the question.
I'm sure it's just a coincidence.
diegof79 1 day ago | parent
OpenAI's reports use language that minimizes their liability.
The first question should be what the organization was doing around those tests, and why they were so naive as to run them without fully isolating the network.
However, all the attention goes to the human-like conclusions in agent thinking traces, which creates a misperception of sentient AI for people who don’t know how the magic black box works.
ofjcihen 1 day ago | parent
For the most part it feels like most people are waking up to it though.
Regarding:
>However, all the attention goes to the human-like conclusions in agent thinking traces, which creates a misperception of sentient AI for people who don’t know how the magic black box works.<
I know there’s been some questions regarding if thinking traces are even relevant to the outcome most of the time.
tptacek 23 hours ago | parent
ofjcihen 22 hours ago | parent
Sort of like the “guns kill people” vs “people kill people” debate.
Deliberate wording to minimize perceived culpability for the agents actions.
tptacek 22 hours ago | parent
ofjcihen 21 hours ago | parent
Now do I think that’s the reason? It certainly isn’t a new thing for companies to try to do that. Shift blame that is.
Regarding civil liability, I’m not making that argument here. But it makes sense from a public perception viewpoint why they would want the agents to appear at fault instead of their own actions.
diegof79 22 hours ago | parent
The agent harness is a process, like any other process in an OS.
You are a researcher running thousands of unattended automations that can hack a website without supervision. The first thing anybody will do is put security at various levels and isolate the network as much as possible. If something escapes your allow list, it should stop the processes as soon as possible.
You cannot foresee a bug in a server (like the Artifactory server in the Hugging Face incident). But you can isolate that server at the network level in the first place. So even if you give that server read-only access, no unexpected packets go out. It's not rocket science; it's something a billion-dollar company experimenting with what they promote as the biggest possible threat to humanity (if they do not handle it) could easily do.
They minimize their liability by changing the message to “oh look how powerful our models are, now we are going to have a public awareness report of the model deviations”. The message should be, “Sorry, we ran experiments without proper sandboxing; it’s our fault, and we changed our testing practices since then.” The former message puts all the blame on the smart, uncontrollable force of AI; the latter is what really happened: an irresponsible test over the Internet.
tptacek 22 hours ago | parent
diegof79 21 hours ago | parent
My argument is very similar to the article in the parent post:
The messages OpenAI published around the recent incidents emphasized their model capabilities but shifted away from their negligence in how they set up and monitor their evaluations.
tptacek 21 hours ago | parent
112233 20 hours ago | parent
Well, here we are.
JumpCrisscross 1 day ago | parent
Legally, this isn’t complete. If it was a genuine mistake and you weren’t reckless, there can be very limited liability.
The AI makers are rich. They can afford to pay. What they can’t afford is complicated adjudications of damages and fault. A system of safe-harbor best practices that cap liability at a penalizing amount that anyone on the other side would be happy with getting quickly and with minimal legal effort is a precedented path forward. Unfortunately, that involves invoking the “r” word.
Avicebron 1 day ago | parent
I feel like the debate is going to come down to what is and isn't considered reckless (both developer and user). Which seems... complicated, with our current LLM/agentic systems.
EDIT: you added more to your comment, the makers have to have some liability. Safe-harbor best practices that cap liability are ripe for abuse.
breadloser 1 day ago | parent
blooalien 23 hours ago | parent
The longer this all goes on, and the deeper the vast majority of folks keep choosing to entrench themselves at one extreme or the other (while being completely unwilling to even consider that there might just be a middle-ground closer to actual reality), the more alarmed I become.
The levels of literal insanity surrounding this technology are how you end up with a real-life "Terminator" scenario, except you're gonna get autonomous killing machines without the time-travel nor any actually intelligent machines. They'll just do their job (killing humans) until we end them, or they end us.
Thankfully, we're not there yet but we do have the exact sorta utterly dangerous completely clueless clowns running around in "the Halls of Power" making the sorts of decisions which bring that reality closer with each passing day. We're really truly screwed if we don't start putting these people under serious scrutiny.
JumpCrisscross 23 hours ago | parent
blooalien 23 hours ago | parent
JumpCrisscross 1 day ago | parent
This is a more productive debate than pretending all AI is fundamentally reckless or should be exempt from all liability, which are the two actual poles of the current dialogue.
> Safe-harbor best practices that cap liability are ripe for abuse
Safe harbors aren’t swimming pools. You can explicitly exempt certain categories of harm from damages. But if an OpenAI bot hacks Hugging Face and causes some chaos but no lasting damage, that strikes me as something a fixed cheque on a fixed scale addresses more effectively than years of litigation or an NTSB-style inquiry.
If, on the other hand, anyone is or could have been injured, no safe harbor. I think it’s important to delineate this, because in the public consciousness the Hugging Face hack is in the same risk bucket as Anthropic’s wet lab.
(I'm a huge fan of the NTSB model for AI. They don't write rules. They mercilessly investigate accidents with full subpoena and records-preservation powers. One of the reasons the debate is so confused is the fact pool we're relying on is highly filtered by industry.)
s1artibartfast 22 hours ago | parent
I see people claiming they aren't being held liable, and some saying it should be situational.
The problem imo is defining what the core function sold is such that you can define malfunction and liability.
JumpCrisscross 22 hours ago | parent
I'd describe David Sacks's position as, approximately, no limits on AI. At some hypothetical future state, sure, maybe, but right now, nothing. That's tantamount to consequence-free action.
reassess_blind 1 day ago | parent
Which one is it? The person behind the wheel when it goes off the rails, or the maker of the software?
Isn’t that part of the question?
thfuran 1 day ago | parent
reassess_blind 1 day ago | parent
xboxnolifes 23 hours ago | parent
kraken_cult 23 hours ago | parent
jknoepfler 1 day ago | parent
blooalien 23 hours ago | parent
no-name-here 21 hours ago | parent
2. If a toolmaker did not build in safeguards, I guess that would mean it’s more likely they’d be liable.
tptacek 1 day ago | parent
senectus1 23 hours ago | parent
the idiocy here is the stupid psudo "AGI" marketing around the services.
its really simple. Whoever run the service to do the task requested is responsible. If OpenAI sent an agent out to train their AI then the directors are to be held responsible, if a user of the service used the service and it inadvertently "hacked" someone then both are held responsible.
throwing AI into the mix changes nothing about how the law is applied. its a tool, like a car or a gun. The user of the tool is responsible for how its used, the manufacturer is also responsible for the safety of it.
belZaah 20 hours ago | parent
bill10 18 hours ago | parent
no-name-here 16 hours ago | parent
mahboi 1 day ago | parent
Sigh, this meme again
bob1029 1 day ago | parent
One of my clients has enforced a policy where a live human user principal must be supplied as a header with any requests outbound from the AI system. The effective policy is that you are completely (100%) responsible for what your agent does on your behalf. The AI system is designed to request confirmation for any potentially destructive actions.
autoexec 1 day ago | parent
Just because a person should be accountable doesn't mean that the AI company can't also be if their service should never have allowed something to happen in the first place, but we're probably going to want actual regulations around what sort of guardrails they're expected to have.
ButlerianJihad 1 day ago | parent
If I speak words in a private space, and a clandestine A.I. spontaneously takes action in the real world based solely on words that I spoke, have I used it? https://m.xkcd.com/1807/
If a business takes my data, like interaction data or a video of me doing stuff, and processes it by A.I, are they using the A.I, or am I using it because it's operating on my input?
If A.I. agents are in my notebook computer, or they are in a cloud server where I have an account, or they are somehow acting while I have them at the command line, but they spontaneously act whether or not I command them, and they work in the background and they work without prompting, but they can also be commanded by direct user prompts... are we using those agents? Or are the agents using us?
https://en.wikipedia.org/wiki/Yakov_Smirnoff#Russian_reversa...
TheRoque 1 day ago | parent
autoexec 1 day ago | parent
If you're just sitting in a car and using it for its intended purpose you wouldn't be accountable for the AI doing something that causes harm.
If some 3rd party, without your knowledge tells AI to act on something you said in video and a reasonable person would expect harm to result from that, the 3rd party would be accountable but you wouldn't be.
> If A.I. agents are in my notebook computer, or they are in a cloud server where I have an account, or they are somehow acting while I have them at the command line, but they spontaneously act whether or not I command them, and they work in the background and they work without prompting, but they can also be commanded by direct user prompts... are we using those agents?
AI agents never "spontaneously act". They have no desires or goals beyond what they are told to do. If you aren't aware of what they were doing, and a reasonable person wouldn't be expected to know what they were doing, you wouldn't be accountable if what they did resulted in harm.
Eddy_Viscosity2 1 day ago | parent
phoghed 1 day ago | parent
By the time it’s an actual problem and not just these guys trying to use it for viral marketing, you’re going to have many thousands of people doing it maliciously with intent to worry about. You’re going to be flooded with Russian hackers with no recourse.
bilekas 1 day ago | parent
The fact this is being discussed as a legitimate question is the real story.
"We trained this beast of processing power, we asked it for a task, and it did something wrong... Who's to blame ?"
Trained on stolen books and material, every word we've all spoken, most lines of code we've ever written with not even an acknowledgment.
Must be the data scientists in their rooms calculating the response rate of every token to blame ? Our version of AI is not sentient. Stop making it seem so. But we need to ask where to look for the culprit ?
jumploops 1 day ago | parent
beloch 1 day ago | parent
What's less obvious is who should be held accountable when a customer of one of these corporations uses their product and it unexpectedly does bad things. e.g. A fellow asks his AI assistant to book him into a high-demand class at the local gym, so the LLM probes the gym's website for vulnerabilities, books him into a date that is farther into the future than the system is supposed to permit, and then drops other people from earlier classes until he's bumped into the one he wanted. If the gym decides to press charges, who should they be applied to?
This sort of case is more difficult to answer. The company that provided the AI certainly bears some responsibility. Perhaps most of it. Possibly even all of it if they represented their AI as reliably law abiding. If a user knowingly uses an AI that is not guaranteed to abide by the law, is that user partially liable for what the AI does too?
IANAL. I'd love to hear perspectives on this question.
throwitaway222 1 day ago | parent
So if an AI agent is asked to build a giant base for someone in MineCraft, and decided to build a swarm of additional agents, and one of those agents says "Time to destroy all humans" and autonomously hacks into the pentagon and fires the nukes - the company that developed the model is responsible. That being said - if the nukes deploy successfully, I have two questions:
1. If no one finds out, is anyone responsible?
2. Was any of this actually real?
tptacek 1 day ago | parent
And they are. I don't think there's any controversy about the civil liability exposure frontier labs have if their agents cause damages, and it is remarkably easy to rack up damages by causing computer intrusions even if those intrusions don't cause obvious direct damages; for instance, many organizations are required to engage forensics firms at nosebleed-high costs to assess the impact of breakins in order to retain insurance coverage.
The "controversy", if you want to call it that, is over criminal liability. People feel that frontier labs should be at least as responsible criminally as human hackers are when they're caught (to be clear: an extraordinarily rare outcome).
The problem is: they're not criminally liable, not so long as the frontier labs operate without specific intent to cause breakins. Mens rea thresholds are their own whole area of criminal law, and there are stark differences between "recklessness" and "intent". All of the meaningful criminal CFAA predicates require actual intent: someone, a human being, has to deliberately set out to create the outcome where a specific intrusion happens. They have to want it to happen and act accordingly. In the most severe cases, they also have to do so with intent to defraud.
We could change the law to make it easier to prosecute breakins without provable intent, but I don't think that would make HN people happier.
mikrl 1 day ago | parent
In both cases, someone ran some software that maybe called other software that ended up doing an action which was possibly illegal.
Downloading journal articles is worthy of punishment but compromising multiple websites is worthy of… heady press coverage?
crorella 1 day ago | parent
bunderbunder 1 day ago | parent
The model’s operator is directly liable for any undue harm caused in the course of the model’s operation. This includes models acquired from third-party vendors. The operator is responsible for ascertaining the model’s fitness for purpose prior to deployment, and for ongoing monitoring of its operation.
If the model came from a vendor, and the operator conducted due diligence but it turns out that the vendor materially misrepresented the model’s capabilities in a way that contributed to the harm, then the vendor can also be held liable.
If that happens then it’s up to a court to apportion the liability.
IANAL but I see no reason why these principles shouldn’t apply to GenAI.
blacksqr 1 day ago | parent
johnea 1 day ago | parent
Unless the money and decision makers are held liable, there will be no impact on the direction of the company.
drivingmenuts 1 day ago | parent
Seems pretty simple to me.
nicflemmer 17 hours ago | parent
Yizahi 13 hours ago | parent
A business plan is not a human right, you know. If I have a nice good idea to make money, but on random it may veer into illegal sometimes, I'm not entitled to just claim innocence because all other times it works in the legal just fine.
Just because uncontained AIs work in the legal most of the time, doesn't excuse people running these programs from when they veer into illegal.
iharuya 5 hours ago | parent