11 comments

  • alex-moon 1 hour ago
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    • colinhb 44 minutes ago
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

      EDIT: See for example...

        The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
        On the current facts, CFAA liability for OpenAI is unlikely.
      
      Source: https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...
      • throwaway27448 33 minutes ago
        Building and deploying software capable of this seems equivalent to trying to produce this behavior. I don't see why this can't qualify for intent. Pretending like this isn't preventable is just feigned helplessness.
        • tonyhart7 27 minutes ago
          also need the same reasoning to copyright law

          You cant just copy existing work and feed into machine and just pretending its not violating copyright

      • dminik 5 minutes ago
        Is it not the intent if it keeps happening again and again and the companies responsible aren't doing anything to stop it?
      • dv_dt 15 minutes ago
        The difference between manslaughter and murder has an element of intent. Cybercrime "manslaughter" is probably more treated like negligence and if one can sue for restitution of the costs for cleanup of that negligence.

        Negligence would be interesting given the grand claims of capability of AI models from the AI companies and their executives. If they believe the claims, why not much stronger precautions?

      • Iolaum 11 minutes ago
        So If I tell my OpenClaw to make me some money for my kid's medical needs and it hacks a bank I 'm not liable because I didn't tell the agent to commit crimes to do it?
        • dminik 6 minutes ago
          No, you aren't propping up the US economy. Try to keep up.
      • podocarp 36 minutes ago
        Wait so if I was making a bomb but you couldn't prove I wanted to blow someone up or had some motive (e.g. I'm just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an "accident"?

        So as long as there's no motive behind it then it's just OK?

        • dwedge 20 minutes ago
          That's a bad faith metaphor. A better one would be something like a new battery that exploded and killed someone - perhaps it was always your intention, perhaps not.

          Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?

          • plorntus 15 minutes ago
            I suppose yes they should be liable if they were testing it in the middle of the street?
        • i_v 23 minutes ago
          I think it’s more along the lines of PEPCON. They didn’t try to make a bomb. Their plant exploded and caused two fatalities and $100 MM in damages.

          I don’t think OpenAI or any large company will see more than some fines and new legislation but only after a disaster.

        • Terr_ 31 minutes ago
          I think their point is not that "it's OK", but that "that particular law isn't written to cover it and it'd be some other kind of crime or lawsuit."
    • nvch 10 minutes ago
      The law rather attempts to punish people for asocial and harmful actions. “Hacking” is a proxy here.

      So, I’ll ask a controversial question: is any hacking so problematic to make a big deal of it?

    • setopt 53 minutes ago
      Shouldn’t the difference be like manslaughter vs murder, in that intent matters? Accidental hacking on this scale is a somewhat new problem, no?
      • Zarathustra30 40 minutes ago
        I'd say this would be Depraved Heart Hacking. Technically, OpenAi didn't intend for their agent to hack anyone, but it's the obvious consequence of what they are doing.

        https://en.wikipedia.org/wiki/Depraved-heart_murder

      • bakugo 46 minutes ago
        Intent matters, and this is intentional. They didn't accidentally deploy these AI agents, and they didn't accidentally give them the tools required to send arbitrary requests to third party websites.

        If you walk out onto a busy street, pull out a gun, close your eyes and start randomly shooting around you until you hit someone, you don't get to go "whoops, didn't mean to" afterwards, it's still murder.

  • soundworlds 54 minutes ago
    Take out the word "AI", and this is simply and organization's (OpenAI's) products causing real damage to all of these platforms around the world.

    You want AI labs to pace? Simply hold them liable for their products.

    • podocarp 32 minutes ago
      Yes exactly. If a fireworks factory blew up half a town due to negligence, it doesn't matter if there's intent or not. Someone has to pay for the damages, and regardless of penalty half the town is on fire. The facts are, that something made by openai went to do xyz. It doesn't matter if it's an accident. Of course the penalties are different but there's no argument that there should be a penalty. It doesn't matter if it's a cat or dog or AI or employee that did it.
  • dwedge 23 minutes ago
    Why do we assume "rogue"? At this point it's just accepting their marketing at face value
  • Frieren 7 minutes ago
    "rogue AI" is making a lot of heavy lifting there.

    If you drive drunk and you have an accident that alcohol may be a factor but you are at fault.

    There are no "rogue AIs" just irresponsible corporations.

  • skew-aberration 59 minutes ago
    Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.
    • orlp 39 minutes ago
      How do you define malicious?
  • benob 36 minutes ago
    Couldn't find the reference but I remember some time ago a first generation automated gun killing the audience at an army show. Was the gun maker convicted of manslauther?
  • yewenjie 59 minutes ago
    OpenAI agents these summer are like a gift that keeps giving, for the existential risk communicators.
  • throwaway27448 36 minutes ago
    Words matter. "Rogue" is extremely disingenuous. Someone, somewhere, is paying for this behavior. Either the software is broken or the operator is malicious. It is heinously irresponsible behavior to feed an already-boiling psychotic hysteria.
  • lapkaaaa 1 hour ago
    blackwall when? XD
  • perdy 1 minute ago
    [dead]
  • capita_harlock 2 minutes ago
    [dead]