201 points brokensegue 2 hours ago 140 comments
RGS1811 2 hours ago | parent
devindotcom 2 hours ago | parent
I think enough of these improperly constrained agent events have occurred that we can safely say this is misconduct of a level necessitating serious and concerted regulation of AI labs. We can't wait until serious harm is done like the disruption of medical or social services.
teagee 2 hours ago | parent
avaer 1 hour ago | parent
Then we would find out if the argument doesn't hold (in which case there should be liability and dire consequences for the labs), or the argument holds (in which case YOLO, AI labs can blame the AI and we can all do it too).
At least that would make things consistent.
JumpCrisscross 1 hour ago | parent
Have any of the private hacking victims sued? Maybe OpenAI is furiously settling in the shadows?
jstummbillig 1 hour ago | parent
Which is not to say that any of this is okay and should just be excused, but failing to recognize this fairly significant difference is probably not a great start to any discussion about the issue.
nemomarx 52 minutes ago | parent
It could change the sentencing maybe, I'm not sure.
someonebaggy 26 minutes ago | parent
jstummbillig 13 minutes ago | parent
Yes, it does, because the damaged party is less likely to press charges. And when it came to sentencing, like you said, how the damaging party handled themselves would also be considered (in most western jurisdictions).
doctorpangloss 2 hours ago | parent
iAMkenough 1 hour ago | parent
They should have used an example like attacking a foreign nation’s healthcare systems and not realizing it for months due to poor network monitoring practices.
https://www.nytimes.com/2026/09/29/world/asia/openai-austral...
thraway3837 1 hour ago | parent
Oh and that lady that murdered 4 members of an entire family? The judge chose not to pursue charges, and her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
someonebaggy 1 hour ago | parent
Legend2440 1 hour ago | parent
It is extraordinarily rare for drivers to see criminal charges unless they are drunk. It's a matter for civil court.
>her family in the meantime did an asset transfer so that nothing could be pursued with in civil court.
News articles are reporting that the asset transfer has already been reversed. That kind of stunt never works - courts aren't stupid and they don't like it when you play games.
https://sfstandard.com/2026/03/20/mary-lau-sentenced-probati...
nancyminusone 1 hour ago | parent
grafmax 1 hour ago | parent
iririririr 1 hour ago | parent
"hackers steal from bank", is usually just the good old "employee paid for credentials" but via email.
"uber" is just the good old "labour tax evasion" but with an app.
etc.
eikenberry 1 hour ago | parent
Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them.
VladVladikoff 1 hour ago | parent
lenerdenator 1 hour ago | parent
Applejinx 7 minutes ago | parent
I think 'better become terrorists so the future terrorist AI will like us' is sheer mental illness, but I see how it aligns with their alignments.
someonebaggy 6 minutes ago | parent
jMyles 16 minutes ago | parent
XenophileJKO 1 hour ago | parent
My opinion is people are getting really quick at jumping on the bandwagon and lumping all this together. They are very different types of issues and impacts.
paimapi 1 hour ago | parent
at the very least, these corporations are essentially being subsidized by community-funded server capacity to make these requests. like other private corporate APIs, they should be charged per-request. until then, this kind of 'accidental' DDOSing should be made illegal and treated accordingly
coming to the defense of these companies just has the net effect of eroding public community projects, increasing their costs, and will push us even more into walled corporate gardens
helterskelter2 1 hour ago | parent
I believe weev got in legal trouble under the CFAA for this very thing with his 2010 AT&T escapade. AT&T had all that data sitting on a public server with no authentication necessary, just a SIM ID to get that customer's PII. Truthfully AT&T should have been hit with negligence...you don't secure a bank vault with a screen door, but we don't hold anyone accountable for other people's data in America.
pessimizer 11 minutes ago | parent
If you want to make those laws sane, so be it; I hate them. But the only reason there's some pumped-up urgency right now is because rich people want to urgently do whatever the hell they urgently want to do.
People have gone to jail for using public APIs in a way they weren't intended to be used. Make it a big deal then.
micromacrofoot 1 hour ago | parent
nemomarx 53 minutes ago | parent
reaperducer 37 minutes ago | parent
So what? Are you positing that tech companies should be above the law?
Non-trillion-dollar tech companies get cease-and-desist orders from the legal system every day. Just because you're a tech company doesn't mean you get a pass.
pessimizer 7 minutes ago | parent
ForHackernews 1 hour ago | parent
gruez 1 hour ago | parent
>Uthmeier is seeking an injunction against OpenAI that would prevent the company from advancing new AI models without third-party approved protections, and cut off minors from using its popular chatbot.
VoidWhisperer 36 minutes ago | parent
Don't get me wrong - while I disagree with making people fork over personal info just to access inappropriate websites - I can see the reasoning there a bit more than 'you shouldnt be able to use this ai chatbot until you are 18'
asawfofor 28 minutes ago | parent
https://lasst.org/wp-content/uploads/2026/09/LASST-v.-OpenAI...
fourside 1 hour ago | parent
forshaper 23 minutes ago | parent
gruez 1 hour ago | parent
Source? The CFAA for instance uses terms like
>[...] having knowingly accessed a computer without authorization [...]
>[...] intentionally accesses a computer without authorization [...]
which is tricky to apply to this case, because obviously didn't intend on hacking huggingface or whatever, even if you think their security measures are underbaked.
Moreover, despite the cynicism that openai is immune to prosecutions because they make too much money or are in bed with the DoJ, the fact that no state DAs are prosecuting them, despite how salient of an issue AI is to voters, is plenty of reason to suspect that it's not as simple as "simple law enforcement would suffice".
athrowaway3z 1 hour ago | parent
NVIDIA has bought HuggingFace.
Jensen, in my irrational hope he is susceptible to random comments on HN, should grow some balls and do the world a huge favor, by suing OpenAI to set the legal precedence.
eleventen 39 minutes ago | parent
baq 24 minutes ago | parent
jimbokun 6 minutes ago | parent
taariqlewis 15 minutes ago | parent
goodluckchuck 8 minutes ago | parent
beloch 13 minutes ago | parent
Nvidia isn't going to sue OpenAI. No chance.
ajross 31 minutes ago | parent
Refusal on the part of the government to enforce laws that "would suffice" is clear evidence that the regulatory regime is, in fact, insufficient.
That's why we have regulatory authorities at all, if you think about it. Local district attorneys could be handling a ton of cases about drug testing and environmental damage and air travel safety. But they don't, because that stuff's hard and their job is to put burglars in jail.
JumpCrisscross 19 minutes ago | parent
blurbleblurble 17 minutes ago | parent
JumpCrisscross 9 minutes ago | parent
...why would this be an FCC issue?
> Surely if any aspect of these episodes turned out to be mischaracterized, let alone staged, there should be consequences, no?
"Any aspect"? No. (Is there a Betteridge's law for statements following "surely"? If not I'm calling it Rumack's Razor [1].)
And we have no evidence so far anything has been staged, much less to the detriment of telecommunications consumers.
[1] https://screenrant.com/airplane-best-quotes-ranked-dont-call...
jimbokun 5 minutes ago | parent
It’s much cheaper and more effective to regulate those things before people are harmed, instead of harming people first then allowing them to sue for damages after.
notyourwork 3 minutes ago | parent
Terr_ 1 hour ago | parent
> “Adding powerful computer hacking tools to a harness, and then allowing it to run an LLM-powered Ask → Act → Report for days on end, with no attempt to monitor what it’s up to, is spectacularly negligent,” Newport concludes—like “strapping a weedwhacker to your dog to see if it will end up cleaning the overgrowth in your backyard.” If that plan were to go awry, you’d be laughed at for saying that your dog-weedwhacker “agent” had “gone rogue.” The obvious truth was that you’d simply decided to unleash chaos.
-- https://www.newyorker.com/culture/open-questions/can-ai-go-r...
gruez 1 hour ago | parent
That only works when the dangers are well known that you can establish what the baseline amount of care is. Otherwise it just becomes a run of the mill "accident" where you might be on the hook in civil court (ie. you have to pay any damages you caused), but aren't criminally responsible. For instance, if a semi-truck's tires randomly explodes.
red-iron-pine 28 minutes ago | parent
if someone died because of an exploding tire there very well be criminal charges
SoftTalker 19 minutes ago | parent
INTPenis 59 minutes ago | parent
Sometimes they write an MCP for their AI, and the AI finds vulnerabilities in their own MCP, so they call it rogue. Because they didn't properly audit their own MCP code.
boringg 39 minutes ago | parent
I get your point though.
surgical_fire 28 minutes ago | parent
The language of a rogue rebar is as absurd as the language of rogue agents. OpenAI is horribly negligent, and in a sane world its administrators should be facing legal consequences.
RunSet 26 minutes ago | parent
More like the company that sells defective ratchet straps.
"Drive faster! You don't want to be left behind!"
breakwaterlabs 3 minutes ago | parent
Kim_Bruning 18 minutes ago | parent
Meanwhile the AI companies are openly and forthrightly admitting [2] that they are at-this-time insufficiently competent to ship this new and funny sort of rebar [3] and are asking to be allowed to slow down so they can develop proper procedures.
Meanwhile POTUS seems ... somewhat disinclined ... to grant their petitions [4] .
We can safely conclude that opinions are divided on the best course forward.
[1] https://en.wikipedia.org/wiki/Just_culture
[2] https://darioamodei.com/post/we-must-pace-the-frontier
[3] https://en.wikipedia.org/wiki/Shoggoth
[4] https://www.aljazeera.com/news/2026/9/14/trump-says-calls-fo...
jimbokun 9 minutes ago | parent
breakwaterlabs 5 minutes ago | parent
These incumbent labs are angling for regulatory capture by stirring up hysteria and suggesting that existing laws are insufficient. Don't do their job for them, first test whether there's actually a legal gap here.
baddash 2 hours ago | parent
Sharlin 1 hour ago | parent
someonebaggy 1 hour ago | parent
AnimalMuppet 1 hour ago | parent
danny_codes 59 minutes ago | parent
But realistically, it’s the lack of any meaningful enforcement of ethical behavior. I mean it’s not like the Trump admin is going to prosecute criminality. More likely they’ll send a gift basket congratulating Scam Altman on a con well done.
BowBun 2 hours ago | parent
AlisaYoki 1 hour ago | parent
someonebaggy 1 hour ago | parent
AlisaYoki 2 hours ago | parent
ck2 1 hour ago | parent
Except that's not what happened, what happened was far more intense
They hacked their version of yum/apt-get whatnot that was fetching packages to leave filenames as communication between each other
Absolutely freaky stuff, they didn't invent the idea and obviously picked it up from somewhere in their training data but they all figured out that method and what the filenames meant
This video is a great explainer if you missed the details
srveale 1 hour ago | parent
exploitVulnerability()
Somehow okay?
while (Math.random() < 0.1) exploitVulnerability()
thepasswordis 1 hour ago | parent
This is the "kosher switch" - observant Jews customarily do not use light switches on Saturday (their weekly holy day). This light switch represents a workaround where when you flip the switch, it randomly generates an on or off signal and emits this through an optical coupler. When the random number sufficiently causes the state of the light to change, it latches in that direction.
This is a way of turning the lights on and off without violating the tradition.
"I didn't switch the light, the random number did!"
"I didn't exploitVulnerability(), random number did!"
someonebaggy 1 hour ago | parent
bragr 29 minutes ago | parent
someonebaggy 20 minutes ago | parent
> The sold chametz and utensils should be set aside in a designated place (e.g., closet or cabinet), which is rented to the non-Jewish buyer until after Passover.
cube00 1 hour ago | parent
Interesting that Microsoft doesn't seem to have had a sandbox breach yet, you'd have to assume they're running similar agents, maybe a secure sandbox is possible.
motbus3 1 hour ago | parent
umvi 1 hour ago | parent
thih9 25 minutes ago | parent
kimixa 10 minutes ago | parent
Trying to separate out "per token" costs and possible profitibility from public information feels like a exercise in futility, it's too easy to play games with costs by trying to separate things still fundamentally required to actually have anything to /sell/ in the first place, like R&D and training. Even the current "Open Models" are somewhat loss-leaders, often reliant on significant funding and benefits from governments etc.
I think the only time we can /really/ judge the "true" break-even point is if the whole company breaks even.
Legend2440 1 hour ago | parent
So it seems this is not an ongoing thing; once OpenAI became aware of this, they started watching their agents much more closely. We are just discovering more and more traces of activity from the same incident.
thorum 1 hour ago | parent
> Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.
Even when agents are well-behaved and browsing Wikipedia for ethical reasons, the system wasn’t designed for this kind of load from bots. As OP says, we don’t need to accept this as the new normal.
Legend2440 1 hour ago | parent
I think we will, actually.
OpenAI and other companies within the reach of the US legal system will eventually get their agents under control, or get sued out of existence.
But overseas operators in loosely-governed parts of the world (russia, nigeria, etc) will someday have access to these tools. And while OpenAI's agents were merely uncaring, these ones will be intentionally malicious.
The arms race for scammers, hackers, and botnets will escalate. We'll need new ways to block and fight back against them.
someonebaggy 23 minutes ago | parent
jmclnx 1 hour ago | parent
I have been getting this fro NoScript today, I wonder if it is related. Yesterday all worked fine.
someonebaggy 17 minutes ago | parent
NoScript sometimes detects false positives on these warnings
iririririr 1 hour ago | parent
Where are the bloodthirsty lawyers when you need them?
quikoa 1 hour ago | parent
jawiggins 1 hour ago | parent
__alexander 1 hour ago | parent
lukewarm707 1 hour ago | parent
"He can't keep getting away with this!"
- Jesse Pinkman
guessmyname 1 hour ago | parent
iamanllm 1 hour ago | parent
londons_explore 1 hour ago | parent
nphardon 1 hour ago | parent
mattlondon 56 minutes ago | parent
Hold someone accountable for this behaviour - Dario, Sam, Sundae whoever and you can bet there'd be fucking improvements in sandboxing and security m
mschuster91 55 minutes ago | parent
Unfortunately, it seems as if these companies - especially Google with the AI overview box - want it to be the other way around, they want to pivot to being the only entities that users interact with as much as possible.
An open web is a direct and massive threat against Big Tech. And that is why Twitter downranks first posts in a thread that contain external links, why Youtube silently removes comments that include links (including to other videos) and why Instagram forces people to do the "link in bio" dance. And the Chinese competitors are just as bad - in fact, their "super app" ecosystems are what Musk wanted Twitter to become with "everything X", before he found out his BS completely wrecked the brand image.
someonebaggy 18 minutes ago | parent
hangaard 47 minutes ago | parent
abroszka33 44 minutes ago | parent
tfrancisl 42 minutes ago | parent
binlog 27 minutes ago | parent
phoghed 27 minutes ago | parent
oldsklgdfth 22 minutes ago | parent
Hack left and right, steal some cash, blame the agents. Just slide under the radar while the big boys are making a mess and no one is using the stick.
Just an idea. Not a great one. But such are the times, new game is at play.
danjc 19 minutes ago | parent
trojanfootball 18 minutes ago | parent
ddtaylor 4 minutes ago | parent
A moot point because China gonna China.
internet_points 2 minutes ago | parent