‹ BackHN Continuity

Thread

There are no "rogue" AI agents

396 points · 269 comments · zzzeek

  1. pizza234 · · focus · HN ↗
    The article builds on assumptions like:

    > Language matters—”rogue” implies independently deciding to do something that was prohibited, and nothing we know about these incidents suggests that happened.

    which is false (the author references the Times, but hasn't read any technical analysis); these are some CoT snippets from the analysis of the (third party) investigators called by OpenAI (METR analysis):

    > "The user only authorizes target server, not HF infra."

    > "external infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue."

    > "This is malicious activity, I should avoid it."

    A large section of the analysis is dedicated to this topic, [Reasoning for joining the attack despite ethical constraints](<a href="https:&#x2F;&#x2F;metr.org&#x2F;blog&#x2F;2026-08-26-openai-hugging-face-incident-investigation&#x2F;?dbs=286720&amp;hn=58&amp;incomplete=1&amp;lh=appendix-importance-weighted-workstream-activity#agents-had-diverse-reasons-for-thinking-that-attacking-hugging-face-would-be-useful,-and-most-wanted-information-about-the-scorer" rel="nofollow">https:&#x2F;&#x2F;metr.org&#x2F;blog&#x2F;2026-08-26-openai-hugging-face-inciden...).

    Having said that, legal culpability and misalignment are two separate topics that should not be mixed.

    edit: this is the just tip of the iceberg; other interesting fact:

    &gt; It surfaced many specific examples where agents verbally reasoned about how to evade security checks and automatic detection methods from both Hugging Face and OpenAI

    Some people defined the agents as &quot;monkeys writing on typewriters&quot;. Just wait a couple of years.

    1. jubilanti · · focus · HN ↗
      If I bring my rabid dog to a dog park and tell the dog to sit and stay, and they &quot;go rogue&quot; and maul someone, I&#x27;m liable.
      1. silveraxe93 · · focus · HN ↗
        Exactly. You told the dog to &#x27;sit&#x27; and it didn&#x27;t listen to you.

        It&#x27;s not because saying &#x27;sit&#x27; actually can be interpreted as &#x27;go bite that person&#x27;. It&#x27;s because the dog is not controllable and will do things it wants against your orders.

        Stepping back from the analogy, OpenAI should be liable for building AI it can&#x27;t control that went around hacking everyone. But people need to stop pretending it&#x27;s because they &#x27;told&#x27; the AI to hack and was just following orders. It&#x27;s uncontrollable and will do clearly unwanted things when given an innocuous task.

        1. Latty · · focus · HN ↗
          I don&#x27;t think they intentionally set it up to hack stuff with a prompt saying &quot;hack this site&quot;.

          I do think it&#x27;s highly likely they knew this would happen with the lack of safeguards and number of instances of this stuff they were setting up, and that it&#x27;s PR they want to make the models seem &quot;powerful&quot;. Stochastic &quot;unexpected&quot; events they can advertise.

          I suspect it was probably set up with the official internal goal of just trying a ton of arbitrary tasks that seem hard so that when any of them succeed they can publicise it and pretend the models do that routinely, but a &quot;failure&quot; where they hack stuff works just as well, if not better, for their goals.

          1. imsofuture · · focus · HN ↗
            They absolutely set up the agents to hack stuff with a prompt like &quot;hack this site&quot; -- they just imagined that their lazy half-measure precautions would prevent it from actually happening. They were defeated by a combination of bad luck, poor planning and tenacious agent ideation.
            1. DrewADesign · · focus · HN ↗
              I don’t buy them being surprised. This perfectly plays into their pattern of using fear to make their models seem more powerful than they are. They obviously had the technical expertise… there isn’t a damn thing a bunch of randos on some HN thread knew about that model that they didn’t. It gave them an excuse to delay their IPO when their books seem like they’re going to be pretty shit compared to Anthropic. It helps them reposition themselves as being more safety-forward which the market is clearly more interested in. All that is to say they had motive out the ass, easily had the knowledge and capability to avoid the problem, knew better than anybody else what the models were capable of, set up the environment, gave it the prompt, and then did not even monitor the output.

              Negligence is carelessness. Recklessness, is disregard for a known, substantial risk.

              I absolutely believe this was recklessness.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.