‹ BackHN Continuity

Thread

There are no "rogue" AI agents

396 points · 269 comments · zzzeek

  1. elric · · focus · HN ↗
    A little over two decades ago, my then girlfriend was arrested for "writing malware" (which was not against the law at the time, and which was never released into the wild and never caused any damage). This set in motion a chain of events that effectively ruined her life.

    Fast forward to today, and we have multi billion dollar corporations pumping out malware at breakneck speeds, compromising various systems (including those of foreign governments), and no one is getting arrested. Instead we're gawking at the marvel of these systems and are playing word games about whether or not it's a rogue system. If anything, it's making people richer.

    Make it make sense.

    1. gruez · · focus · HN ↗
      >A little over two decades ago, my then girlfriend was arrested for "writing malware" (which was not against the law at the time, and which was never released into the wild and never caused any damage).

      Criminal law places a lot of emphasis on intent, hence laws about the mere possession of breaking and entering tools, and the old adage about always bringing along gloves and baseball if you want to carry around a baseball bat. Without more details about your specific case, my guess is that she did indeed write malware or hacking tools, and there were vague signs it wasn't purely academic, hence why they threw the book at her.

      That's all in contrast to whatever the AI labs are doing, which might have actually resulted in people getting hacked, but you'd have a hard time arguing that they were intending on that to happen. Maybe if the targets end up being anti-datacenter activists or other AI labs you might have a better case, but they did vaguely try to contain the model. Moreover "hacking tools" aren't even illegal, if you have a plausible non-criminal (ie. security) angle, eg. nmap. The same could be argued for AI models, even if they're running them against exploitgym or whatever. Having an army of lawyers to defend yourself doesn't hurt either.

      1. datsci_est_2015 · · focus · HN ↗
        “Sorry officer, I didn’t intend to shoot her, I was just firing my gun wildly and she got in the way.”

        I don’t know why I’m seeing this rationalization so much in this forum when this topic comes up. Negligence is a concept in law as well. You don’t have to squint to see that irresponsible use of code-generating language models is criminally negligent.

        1. wildzzz · · focus · HN ↗
          That's why we have different criminal statutes for homicide.

          If you're at a gun range looking down a scope and someone crosses right in front of your gun as you fire, you would probably be fine since you were shooting responsibly and had no way to see them until it was too late.

          If you're at a gun range and that backstop is deficient such that a bullet passes through and hits someone, again, probably not liable but the gun range may be since they built a bad backstop and let people use it.

          If you are at a gun range and lose control of an automatic weapon and kill someone, you may be liable for negligence because you were using a gun you couldn't control.

          If you are cleaning your gun and it goes off because you forgot to check if it was loaded, again, criminal negligence.

          If you threaten someone with a gun and they get shot while trying to wrestle it away from you, that may be some form of manslaughter. You had no intention of shooting them but the act of threatening them with it created a situation where the other person died. Same with killing someone while drunk driving, you didn't mean to crash your car but you did something to create the risk.

          If you plan to kill someone, it might be the top tier of homicide charges but it depends on how much planning went into it. If you walked in on your spouse cheating and went to grab a gun to shoot the affair partner, maybe a lighter form of murder than if you made a plan to track the affair partner to their house and killed them there.

          Simply put, there are a multitude of ways you can be charged with a crime that takes into account your intentions and forethought. Did someone intend for these agents to escape their sandbox? Did they do their due diligence in building a sandbox such that it would be difficult for agents to escape? Just like with all software, a reasonable person assumes that nothing is bulletproof, spend enough time and money and you can probably find a vulnerability. The question is does a reasonable person think that this sandbox should have kept an agent contained?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.