‹ BackHN Continuity

Thread

Who should be held accountable when an AI Agent (accidentally) acts maliciously?

37 points · 99 comments · Greenpants

  1. CatDaaaady · · focus · HN ↗
    I don't see how this is such an unclear legal question. If I fire a computer program that mistakenly causes another person harm, its my fault. Or it would be the maker of the program's fault. I feel we have established pattern for this already.

    Until we can agree whether AI is conscious, which we never will, AI and AI agents are just property working on behalf of humans.

    I could see a future where AI companies/services indemnify consumers who use their agents but _not_ indemnify corporations that use their services.

    1. JumpCrisscross · · focus · HN ↗
      > If I fire a computer program that mistakenly causes another person harm, its my fault

      Legally, this isn’t complete. If it was a genuine mistake and you weren’t reckless, there can be very limited liability.

      The AI makers are rich. They can afford to pay. What they can’t afford is complicated adjudications of damages and fault. A system of safe-harbor best practices that cap liability at a penalizing amount that anyone on the other side would be happy with getting quickly and with minimal legal effort is a precedented path forward. Unfortunately, that involves invoking the “r” word.

      1. Avicebron · · focus · HN ↗
        > you weren’t reckless

        I feel like the debate is going to come down to what is and isn't considered reckless (both developer and user). Which seems... complicated, with our current LLM/agentic systems.

        EDIT: you added more to your comment, the makers have to have some liability. Safe-harbor best practices that cap liability are ripe for abuse.

        1. JumpCrisscross · · focus · HN ↗
          > the debate is going to come down to what is and isn't considered reckless

          This is a more productive debate than pretending all AI is fundamentally reckless or should be exempt from all liability, which are the two actual poles of the current dialogue.

          > Safe-harbor best practices that cap liability are ripe for abuse

          Safe harbors aren’t swimming pools. You can explicitly exempt certain categories of harm from damages. But if an OpenAI bot hacks Hugging Face and causes some chaos but no lasting damage, that strikes me as something a fixed cheque on a fixed scale addresses more effectively than years of litigation or an NTSB-style inquiry.

          If, on the other hand, anyone is or could have been injured, no safe harbor. I think it’s important to delineate this, because in the public consciousness the Hugging Face hack is in the same risk bucket as Anthropic’s wet lab.

          (I'm a huge fan of the NTSB model for AI. They don't write rules. They mercilessly investigate accidents with full subpoena and records-preservation powers. One of the reasons the debate is so confused is the fact pool we're relying on is highly filtered by industry.)

          1. s1artibartfast · · focus · HN ↗
            Have you ever seen someone claiming ai labs should have no liability in the wild? I haven't.

            I see people claiming they aren't being held liable, and some saying it should be situational.

            The problem imo is defining what the core function sold is such that you can define malfunction and liability.

            1. JumpCrisscross · · focus · HN ↗
              > Have you ever seen someone claiming ai labs should have no liability in the wild? I haven't

              I'd describe David Sacks's position as, approximately, no limits on AI. At some hypothetical future state, sure, maybe, but right now, nothing. That's tantamount to consequence-free action.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.