Live data from Hacker News

Iowa-led states ask OpenAI to keep their bots on a leash

iowaattorneygeneral.gov

101–110 of 129 posts

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#101
post #23

Earlier quoted context omitted.

Nobody stole from humanity, constantly told us how dangerous the invention was, and then set up systems that they couldn’t properly control to rush ahead of their competitors? Nobody did that on purpose? I think they did.

You could say that same exact thing for the entire Industrial Revolution, but that doesn't mean we are going to destroy the looms even though some tried unsuccessfully.

Ok and? We can do better this time but let’s just not so the capitalists can crush normal people yet again?

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#102
post #44

Earlier quoted context omitted.

A crime was committed, if there is enough evidence then the state is required to prosecute and the victim has not choice in this. The victim can say they don't care and that will often hold weight for the prosecution, but that is the government's choice not the victims. The victim sometimes file a civil lawsuit against the criminal, that is their choice. That is not a criminal matter though and different rules apply.…

The "victim" doesn't have the final choice but their position is heavily influential and prosecutors don't decide if a crime was committed, that only happens at the end of the judicial proceedings. Calm down.

If somebody fires a gun in a place where that's not allowed, the victims are everybody in that place. If it just so happens that the bullet struck a window, the owner of that window might be an additional victim for an additional crime but that doesn't negate the first crime.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#103

Earlier quoted context omitted.

"Without whatever intent the crime requires, they haven't committed a crime." I'm not a lawyer, but I don't believe this. There is definitely negligence, these companies have often talked about the danger of AI. They have often written about how their AI is breaking out of sandboxes or trying to manipulate the person tuning it. They should have had stronger guards and monitoring in place.

Shouldn't the very act of sandboxing the AI be enough of a defense against criminal negligence? Maybe they use the best sandbox available and the AI hacks through it anyway by discovering some zero day or something. They still demonstrated enough prudence to at least attempt to sandbox the AI. Criminal negligence would be "nah nothing's gonna happen" followed by YOLOing it then going home for the weekend.

Generally, yes, sandboxing would be a defense, because criminal negligence (again, it's state specific, so this is a law-school-level generalization) requires "gross deviation from the standard of reasonable care". So a mistake in judging the kind of sandbox or isolation you need would not be criminal negligence unless that mistake fell into the above category. I can't think of a case where it would or has - courts have consistently held mistake of judgement to be below criminal negligence in every case i'm aware of. I'm sure it's happened somewhere though.

As i mentioned elsewhere, the standard is basically "total disregard for safety in the face of an obvious and huge risk that resulted in injury or death". I don't think anything we are talking about here comes close to these criteria.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#104
post #93

Earlier quoted context omitted.

Shouldn't the very act of sandboxing the AI be enough of a defense against criminal negligence? Maybe they use the best sandbox available and the AI hacks through it anyway by discovering some zero day or something. They still demonstrated enough prudence to at least attempt to sandbox the AI. Criminal negligence would be "nah nothing's gonna happen" followed by YOLOing it then going home for the weekend.

Maybe. However they used a flaws sandbox when they could have physically not connected any computer to the internet (including wifi)

The existence of alternatives would generally not be enough for criminal negligence.

Making mistakes of reasoned judgement are basically never criminal negligence.

In every state i'm aware of, it would require total disregard for safety in the case of a huge and obvious danger.

It would also have to cause injury or death.

The bar for criminal negligence is pretty high.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#105

Earlier quoted context omitted.

"own" in the sense of "be responsible for the consequences". Not in the sense of "be able to grant reproduction rights".

That's how I interpreted it. I just wanted to highlight what I see as a discrepancy. They're putting all the liability on us because it's a tool with no intent of its own while simultaneously saying prompts don't count as creativity because it's not a tool like a photographic camera it's just a casino where you roll the dice. Quite self-contradictory in my opinion.

The copyright office’s guidance is that prompts are covered by copyright, it is the output of an LLM that one cannot claim ownership of.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#106

If Waymo can be liable for their cars, why isn't OpenAI liable for its AI?

Who says they aren’t? But it’s unclear how much damage they did and the attacked companies haven’t sued, yet.

Criminal liability doesn't require civil suit.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#107
post #19

Earlier quoted context omitted.

No law needed, that's the way it already is.

Lawyer here. Not quite. Agents in the principal/agent sense have to be human. However, every court to have ever considered it have held the human/company driving the agent responsible under vicarious liability/negligence/etc principles. The only real defense that folks have tried is to claim the agent acted "autonomously", which no court has bought so far.

Then we agree right?

>Make a law that someone is responsible for a bot's actions

Original comment suggests creating a law such that a person is responsible for a bot's actions.

I mention that no law is needed since people are already responsible for bot's actions.

You mention that courts consider human/companies are responsible for their agents. And that defenses about agents acting autonomously are not successful in courts.

Therefore a law that makes people responsible for bot actions is not needed, as that's the way it already is.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#108
post #93

Earlier quoted context omitted.

Maybe. However they used a flaws sandbox when they could have physically not connected any computer to the internet (including wifi)

The existence of alternatives would generally not be enough for criminal negligence. Making mistakes of reasoned judgement are basically never criminal negligence. In every state i'm aware of, it would require total disregard for safety in the case of a huge and obvious danger. It would also have to cause injury or death. The bar for criminal negligence is pretty high.

We need details of the exact facts before we can say if they met any bar. Was their sandbox something from 2005 that has a ton of known holes, or something modern?

There are two sides of this.

First the AG are checking to see if they really took enough care or not. If they didn't then I expect criminal negligence. Even if they took care I want them to feel some pain from the investigation because their care wasn't enough to work.

Second I want them to verify the laws are correct. This is a new area and there might be loopholes that need to be closed. Regardless of the law, there was a successful attack and that should not be allowed.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#109

Earlier quoted context omitted.

The existence of alternatives would generally not be enough for criminal negligence. Making mistakes of reasoned judgement are basically never criminal negligence. In every state i'm aware of, it would require total disregard for safety in the case of a huge and obvious danger. It would also have to cause injury or death. The bar for criminal negligence is pretty high.

We need details of the exact facts before we can say if they met any bar. Was their sandbox something from 2005 that has a ton of known holes, or something modern? There are two sides of this. First the AG are checking to see if they really took enough care or not. If they didn't then I expect criminal negligence. Even if they took care I want them to feel some pain from the investigation because their care wasn't en…

I still don't understand exactly which facts you think any of this would change and cause it to be criminal negligence.

I will state a fairly blunt position: Unless literally nobody thought or tried at all here, i would give it a 0% chance of meeting the bar of criminal negligence.

The rest is a distinction without a difference.

As for what you want them to do - i don't agree the investigation should cause them to feel pain - that's not a good goal for investigations, and definitely not one we should want, because it essentially presumes they did somethign wrong in the first place. A bad outcome does not mean a broken process. All processes have error bars. You can desire the error bars to be smaller, and try to back that up with criminal penalties, but an expectation that error bars will be 0 makes no sense.

You can do absolutely everything right and still have people die - star trek was not wrong in that regard. Punishing that will not fix this inconvenient reality, which is why we generally don't punish it. This is also why we distinguish between inherently dangerous activities and not, for example.

As for the laws, sure, i think it's totally reasonable to explore whether you want the law to be different, but again, i totally disagree with your second part.

A successful attack does not imply anything is actually wrong with criminal law, or should be changed. The question is more of what error bars you want on the activity and where what they did falls - inside or outside those error bars.

Re: Iowa-led states ask OpenAI to keep their bots on a leash

#110
post #92

Earlier quoted context omitted.

> The threat of semi-autonomous AI threat actors will never go away until the financial incentive that buoys unchecked growth at all costs goes away. It's not going away unless computers themselves go away or become massively less powerful. Open weights exist. They're out there. This is an irreversible change. The democratization of persistent cybersec threats is completed and won't be rescinded.

Somebody is supplying power to those AIs. That somebody can be charged for not taking care of their AIs (that is not pulling the plug). Sure this then turns into international crimes, but not allowing crimes to be committed on your side of the border is a big help even if we can't get everything.

The problem is that law is reactive, and punishment entails the harm already happened. Some dumbass kid getting convicted for committing a cybercrime with AI doesn't do anything to get rid of the structural problems that enabled it. That conviction can only happen if the harm happened in the first place, and the problem is the harm itself. It's like trying to solve a mold problem by targeting a single fruiting body. You're not really doing anything.

On top of that, it's not really any consolation if the advanced persistent threat gnawing at my ports lives in a different country either. That doesn't help in the slightest.

Post reply on HN