This is a wrong-headed attempt to regulate AI. The real problems are different.
AI systems, especially multi-agent ones that can do things, are more akin to corporations, than individuals. When you read the logs from the Hugging Face incident, you're seeing something that looks a lot like internal corporate emails. Various units of the organization are arguing over what to do and who does what. They eventually converge and get the job done, breaking the rules at times. This is normal corporate behavior.
When agentic AIs do something outside their own internal world, they do it by engaging in transactions with external systems and people. As yet, few have robots to do their bidding.
So, again, this is normal corporate behavior.
A corporation is a goal-seeking system. In theory, if you agree with Milton Friedman, its sole purpose is to maximize shareholder value. Internally, within the company, there are subgoals, which exist to support the top level goal. That, too, is what multi-agent AIs do.
The uncomfortable place this thinking leads is that AI regulation and corporate regulation are very similar. That's not something the political part of the world wants to think about too hard.
It would mean putting more constraints on corporate power.
Yet that can't be ignored, because we're likely to see corporations where some parts are AI and some parts are human. That's already been done a few times as a demo, not too successfully. Yet.
It's going to hit hard when an AI-run company outperforms a human one.
"more constraints on corporate power" assumes that the existing ones are functional, which they arguably are not.
If we enforced existing laws against unauthorized access to someone else's computer resources against the companies who run a model that hacks someone else, rather than buying their "The agents did it, we're not responsible" BS, then maybe the incentives to behave responsibly would improve.
OpenAI immediately disclosed the hack and submitted to both internal and external investigations, and published extremely detailed breakdowns of what happened. How is that not taking responsibility?
> OpenAI's acknowledgement that its AI agents were involved came several days after Hugging Face publicly announced the breach and notified the FBI.
The penalty for "unauthorized access to a computer system" is 1 to 20 years in prison[1]. Holding corporations accountable would include sending the highest person in the chain-of-command that caused the Hugging Face incident to jail. Or at least start with some charges and then let the judicial system do its thing.
[1] 18 U.S. Code § 1030 - Fraud and related activity in connection with computers <a href="https://www.law.cornell.edu/uscode/text/18/1030" rel="nofollow">https://www.law.cornell.edu/uscode/text/18/1030
To what end? What would that force OpenAI to do that they are not already doing in response to the incident?
They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight.
You put people in jail
if the other incentives aren’t enough.
We have a system of law and order that puts people in prison if they commit crimes.
> To what end? What would that force OpenAI to do that they are not already doing in response to the incident?
You could ask this (and people have done) of any criminal code. It doesn't matter. The law is not there to rehabilitate, it's there to punish and thereby deter.
> They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight
If a person breaks the law, the state prosecutes them (or can choose to), we don't require the victim to press charges. For good reason - threatening the victim to not press charges would be a way of avoiding consequences.
> You put people in jail if the other incentives aren’t enough.
This is incorrect. We put people in jail as a result of them breaking the law, regardless.
We absolutely should apply this principle to corporations as well as citizens. Aaron Schwartz died for less.
> The law is not there to rehabilitate, it's there to punish and thereby deter.
Technically, it's neither. The law is there to state what ought to be. Even putting that aside, it's prescribed punishment's goal is to remediate and prevent violations of the law, so it has three simultaneous means: to restitute, to deter and to rehabilitate. The balance between the three is predicated on each's ability to satisfy the original goal of remediation and prevention, all the while not violating other laws and rights.
> We put people in jail as a result of them breaking the law, regardless.
A core principle of the rule of law is the principle of proportionality, which states that only the most legal amount of force is the materially sufficient enough to prevent a crime. If lower measures are sufficient to prevent a crime, jailing should not be prescribed, not only to respect the law but also to make good use of scarce resources, as prison overcrowding may not only reduce their effectiveness, but also open the door for downstream right violations.
we have minimum sentence rules, we jail people for possession of drugs when jail has been proven to not prevent or cure addiction.
Yes there are principles of the rule of law, but they've been thrown out of the window in favour of whatever sounds like "strong on crime".
> could have been sued by HF if HF chose to do so
Hugging Face was another AI company. Do you see many of those suing each other and especially the top dogs in the field? Also, do you think it's a coincidence NVIDIA bought Hugging Face ASAP to stop any damaging anti AI waves from happening?
The other incentives aren't enough. All the labs are basically Russia against Ukraine in 2022-206: launching high caliber imprecise ballistic missiles against military targets surrounded by civilians. Whoever orders that knows civilians will do die but doesn't care.
AI labs aren't using proper sandboxing measures for their agents because that would slow down their testing. Plus any hacks that happen, short of breaking into Trumps social media accounts, only cause the kind of publicity they want.
Hugging Face disclosed the attack. OpenAI owned up to it a week later. It's unclear when and if OpenAI would have disclosed it if HF hadn't already done so.
For a more recent example, OpenAI was chastised by Australia recently for notifying them three months after their agents attacked AUS government websites.
Animats · · focus · HN ↗
AI systems, especially multi-agent ones that can do things, are more akin to corporations, than individuals. When you read the logs from the Hugging Face incident, you're seeing something that looks a lot like internal corporate emails. Various units of the organization are arguing over what to do and who does what. They eventually converge and get the job done, breaking the rules at times. This is normal corporate behavior.
When agentic AIs do something outside their own internal world, they do it by engaging in transactions with external systems and people. As yet, few have robots to do their bidding. So, again, this is normal corporate behavior.
A corporation is a goal-seeking system. In theory, if you agree with Milton Friedman, its sole purpose is to maximize shareholder value. Internally, within the company, there are subgoals, which exist to support the top level goal. That, too, is what multi-agent AIs do.
The uncomfortable place this thinking leads is that AI regulation and corporate regulation are very similar. That's not something the political part of the world wants to think about too hard. It would mean putting more constraints on corporate power.
Yet that can't be ignored, because we're likely to see corporations where some parts are AI and some parts are human. That's already been done a few times as a demo, not too successfully. Yet. It's going to hit hard when an AI-run company outperforms a human one.
zdw · · focus · HN ↗
If we enforced existing laws against unauthorized access to someone else's computer resources against the companies who run a model that hacks someone else, rather than buying their "The agents did it, we're not responsible" BS, then maybe the incentives to behave responsibly would improve.
derekdahmer · · focus · HN ↗
voidhorse · · focus · HN ↗
<a href="https://en.wikipedia.org/wiki/OpenAI%E2%80%93HuggingFace_incident" rel="nofollow">https://en.wikipedia.org/wiki/OpenAI%E2%80%93HuggingFace_inc...
Swizec · · focus · HN ↗
The penalty for "unauthorized access to a computer system" is 1 to 20 years in prison[1]. Holding corporations accountable would include sending the highest person in the chain-of-command that caused the Hugging Face incident to jail. Or at least start with some charges and then let the judicial system do its thing.
[1] 18 U.S. Code § 1030 - Fraud and related activity in connection with computers <a href="https://www.law.cornell.edu/uscode/text/18/1030" rel="nofollow">https://www.law.cornell.edu/uscode/text/18/1030
derekdahmer · · focus · HN ↗
They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight.
You put people in jail if the other incentives aren’t enough.
marcus_holmes · · focus · HN ↗
> To what end? What would that force OpenAI to do that they are not already doing in response to the incident?
You could ask this (and people have done) of any criminal code. It doesn't matter. The law is not there to rehabilitate, it's there to punish and thereby deter.
> They’ve already opened themselves up to liability, could have been sued by HF if HF chose to do so, and are literally lobbying for government oversight
If a person breaks the law, the state prosecutes them (or can choose to), we don't require the victim to press charges. For good reason - threatening the victim to not press charges would be a way of avoiding consequences.
> You put people in jail if the other incentives aren’t enough.
This is incorrect. We put people in jail as a result of them breaking the law, regardless.
We absolutely should apply this principle to corporations as well as citizens. Aaron Schwartz died for less.
bit-anarchist · · focus · HN ↗
Technically, it's neither. The law is there to state what ought to be. Even putting that aside, it's prescribed punishment's goal is to remediate and prevent violations of the law, so it has three simultaneous means: to restitute, to deter and to rehabilitate. The balance between the three is predicated on each's ability to satisfy the original goal of remediation and prevention, all the while not violating other laws and rights.
> We put people in jail as a result of them breaking the law, regardless.
A core principle of the rule of law is the principle of proportionality, which states that only the most legal amount of force is the materially sufficient enough to prevent a crime. If lower measures are sufficient to prevent a crime, jailing should not be prescribed, not only to respect the law but also to make good use of scarce resources, as prison overcrowding may not only reduce their effectiveness, but also open the door for downstream right violations.
marcus_holmes · · focus · HN ↗
Yes there are principles of the rule of law, but they've been thrown out of the window in favour of whatever sounds like "strong on crime".
oblio · · focus · HN ↗
Hugging Face was another AI company. Do you see many of those suing each other and especially the top dogs in the field? Also, do you think it's a coincidence NVIDIA bought Hugging Face ASAP to stop any damaging anti AI waves from happening?
The other incentives aren't enough. All the labs are basically Russia against Ukraine in 2022-206: launching high caliber imprecise ballistic missiles against military targets surrounded by civilians. Whoever orders that knows civilians will do die but doesn't care.
AI labs aren't using proper sandboxing measures for their agents because that would slow down their testing. Plus any hacks that happen, short of breaking into Trumps social media accounts, only cause the kind of publicity they want.
harimau777 · · focus · HN ↗
sillyfluke · · focus · HN ↗
For a more recent example, OpenAI was chastised by Australia recently for notifying them three months after their agents attacked AUS government websites.
[0] <a href="https://news.ycombinator.com/item?id=49825580">https://news.ycombinator.com/item?id=49825580