‹ BackHN Continuity

Thread

Early rogue AI agent activity and attempts to hack found on urlquery.net

267 points · 313 comments · snikolaev

  1. alex-moon · · focus · HN ↗
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    1. colinhb · · focus · HN ↗
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act

      EDIT: See for example...

        The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
        On the current facts, CFAA liability for OpenAI is unlikely.
      
      Source: <a href="https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai-hugging-face-incident-exposed-the-cfaa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai...
      1. DannyBee · · focus · HN ↗
        Lawyer here: CFAA is mostly criminal statute not a civil one (civil damages require proving more than a violation so also require specific intent)

        Almost all common felonies require specific intent. Misdemeanors often do not.

        There is plenty of civil liability available.

        If you wanted them to be charged with a felony you would need changes. I would strongly suggest you do not want a strict liability felony.

        The cfaa required intent is as follows :

        * § 1030(a)(5)(A): knowingly transmits code&#x2F;commands and intentionally causes damage without authorization.

        * § 1030(a)(5)(B): intentionally accesses without authorization and recklessly causes damage.

        * § 1030(a)(5)(C): intentionally accesses without authorization and causes damage and loss;

        Simply changing the first intentionally to intentionally or recklessly would cover OpenAI (now that they know it can occur) without causing lots of other issues. Without that, they don’t have the intentionality necessary to meet the first part, even if they would otherwise meet the second part

        1. digitaltrees · · focus · HN ↗
          Why do we have to attribute intentionally to a human. The AI agent is capable of making plans and then effectuating them. They are acting on behalf of a user but under authority granted by the user to take independent action on the users behalf and authorized to devise their own plans. I think that would justify attributing intentionally to the AI agent without needing to look to openAI or the user. I would then say the user and labs are clearly aware of and on notice of this behavior and are behaving recklessly in all the agent to act without supervision.

          I think the labs risk being barred from releasing further AI if they don’t get this under control.

          If they aren’t careful and keep rushing to distribute systems they know they can’t control then AI should be treated like a wild animal. The law is clear on establishing strict liability for the owners of wild animals; if you own a tiger and it kills someone you can’t hide behind “I didn’t intend” the harm the nature of the tiger is known and you are responsible for it’s actions.

          1. ubercore · · focus · HN ↗
            Can&#x27;t charge an AI agent itself with a felony, so intent or reckless behavior would have to be assigned to a person or corporation, I&#x27;d think.
            1. digitaltrees · · focus · HN ↗
              You can charge the company based on the behavior of employees&#x2F;human agents.

              I am suggesting we can charge the company based on AI agents actions because the company has authorized them to act independently on the company’s behalf. The question is what factual analysis gives rise to the charge, is it the intention of the agent or intention of the company. I am arguing that because the agents are defining their actions independently and the company knows that and still allows them to act independently the only reasonable factual analysis is to look at what the AI agent intended. And we don’t need to have the agent tell us its intent we can look at its actions and infer just like we do with humans in similar circumstances

              1. pixl97 · · focus · HN ↗
                If I were a state I&#x27;d want to be very careful before flinging out charges as this is going to set precedence for a long time to come. Screw it up too bad and as it raises though the appeal courts and you may unintentionally give corporations a lot more free reign than intended. The wheels of the law are typically very slow, the state has years before it has to indict.

                We also don&#x27;t know how many other political processes are occurring here. At least at the state&#x2F;federal levels the people that would bring charges may be getting pressure not to.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.