gizajob
a day ago
Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be:
OpenAI meddled with multiple US Government agency sites.
The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.
20k
a day ago
Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?
It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?
In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this
This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem
>"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.
This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up
0xDEAFBEAD
a day ago
>line go up
It's already going up at staggering rate. Anthropic is now at $100B in annualized revenue, up 50% in the past two months.
* * *
Here's a little allegory for how I'm thinking about this discourse.
Imagine a man who is raising tiger cubs in his backyard. They're growing fast. He keeps them on dog leashes so they stay under control. One day, a growing cub breaks its leash and goes on a rampage through the neighborhood, eating a beloved local pet.
The neighborhood erupts into a big argument: Was the leash inappropriately thin? The neighbors point out that thicker leashes are easily available at the local pet store. Furthermore, is it appropriate to refer to the loose cub as a "wild animal" in local news reporting, or is it factually more accurate to call it "domesticated"?
Meanwhile, the cubs grow larger and lick their lips, oblivious to the discussion.
gizajob
a day ago
The city or his neighbours would be like “you can’t keep tigers in the backyard sir”.
0xDEAFBEAD
a day ago
Yes, that would be the common sense response from my perspective: https://pauseai.info/
4d4m
a day ago
There is no reason to pause any AI development. Quite honestly there is very little appetite to be left last.
However, there is a reasonable ask from the public to hold real people accountable for actions downstream of the software allowed to carry out intendended and unintended actions that may not be allowed depending on jurisdictions laws.
Eg in a hypothetical armed convenience store theft: We don't prosecute the gun manufacturer, we prosecute the individual using the weapon for crime. Same deal here.
0xDEAFBEAD
a day ago
>There is no reason to pause any AI development. Quite honestly there is very little appetite to be left last.
"According to survey results released on Wednesday, 68% of [likely US voters] said they would support the proposal to temporarily pause advanced AI development and permanently prohibit the development of superintelligent programs, while just 25% said they’d oppose it."
https://www.commondreams.org/news/sanders-casar-ai-bill-poll
>Eg in a hypothetical armed convenience store theft: We don't prosecute the gun manufacturer, we prosecute the individual using the weapon for crime. Same deal here.
So if I ask ChatGPT to make me some paperclips, and it replaces all the matter in a nearby city with paperclips, who gets prosecuted: me, or OpenAI?
idiotsecant
8 hours ago
This policy only makes sense if legislative action is effective against orgs outside the US. Otherwise it's not even worthless, it's worse. It moved more development outside the grasp of regulation.
4d4m
a day ago
In this stretch of a hypothetical, you the user
0xDEAFBEAD
a day ago
Well in that case, OpenAI has reduced incentive to solve the alignment problem, since it won't suffer liability from alignment failures.
morpheos137
20 hours ago
Also the policy makers that made infrastructure and laws susceptible to automated manipulation which decidedly is not the case today. For example LLMs are not able to manipulate the power grid because they are not exposed to the control interfaces..no matter how intelligent llms get their physical levers do not extend unless people decide to let them. The ai threat is real ridiculous.. yes you may ee ome uplift in bad actor. Like for example f someone wants to build a tank dozer in their garage and is not experienced welding ai might give some useful information as a book would in the past. However just like a book ai is bot going to build and operate it itself unless someone design and effective android robot. Once LLMs or other ai becomes an embodies agent then there may be a real threat if agency. Last time I checked ai can't drive a car but it can tell you to walk your car to a car wash.
bwfan123
16 hours ago
> The ai threat is real ridiculous
It is an elaborate business ploy to create a regulatory framework for "safe-ai" that shields these companies from liability. This way, they can sell "safe-ai" to enterprises and if shit-hits-the-fan at the enterprise, sorry, this is certified "safe-ai" so, your bad. Shift blame to a regulatory body. From an enterprise buyer's perspective they can say, hey, I bought "safe-ai" and so dont fire me when it "rm -rfs" the production database. Still, beats me why they are painting their product in a negative light, and scaring their own enterprise customers. After this sort of marketing, any enterprise buyer would be scared to go anywhere near it.
TomGarden
a day ago
if these models will eventually be as powerful as projected, these models should not be likened to guns, but to nukes. Which yes, if you manufacture nukes, we prosecute you
gizajob
a day ago
It’s my common sense response to tigers. My thoughts about AI are varied and many yet lean towards the skeptical.
jsnell
a day ago
These were evaluations or training runs dealing with the ability to do web searches. The entire reason the bots were targeting this site is that it had some of the data they'd been tasked with finding. Access to the internet is not really optional for that, and providing internet access doesn't demonstrate neglicence.
> This is why it smells like marketing
It doesn't. "Our product commits felonies" is not marketing. If something is marketing, you don't engage in repeated coverups of the true extent. If something is good news, you don't release it on a Friday evening (in this case) or wait for 3rd parties to find and publicize the evidence (the past cases).
8note
a day ago
> The entire reason the bots were targeting this site is that it had some of the data they'd been tasked with finding.
so openai specifically tasked the agents with meddling in US government websites?
id say tasking them with getting data from there as swapping from negligence to malice.
jsnell
a day ago
No. They tasked them with answering questions by retrieving data from public sources. This obviously requires internet access. So the incredulity about "how could they fail to block internet access" is just inane. That was the task.
They did not task the agents with hacking into systems. Not monitoring for that was a mistake, but maybe a forgivable one the first time around. The subsequent coverups are inexcusable.
tough
a day ago
Usually also, and more so nowadays, a few of the public sources of data left, even after the recent USGov intention of defund and close as much of them as possible, im guessing would be precisely, government websites!
jacquesm
a day ago
> It doesn't. "Our product commits felonies" is not marketing.
Oh, absolutely it is. Arms manufacturers always go on about the efficiency of the weapons they create and make no mistake: OpenAI is first and foremost a weapons manufacturer, the rest is just a fig leaf. The fact that you aren't the audience for purchases like that makes no difference. "Look at this capability, and that's when we're not even trying." is pretty good marketing in some circles.
jsnell
a day ago
Yes, famously tobacco companies wanted to advertise their products as addictive and deadly. That's why they funded and heavily publicized research to that effect.
Climate change is just a scam by the fossil fuel industry to hype up their market cap. Look at the power of co2, and the damage it can do without even trying.
Medicines being pulled during trials or after public availability for side effects are just Big Pharma making their products more desirable via scarcity.
Boeing did really well out of the 737 max. Airlines were just lining up to buy an airplane that could give the passengers an experience they would remember for the rest of their life. That's why they absolutely made clear that it was their product that was dangerous, rather than blaming operator error.
jacquesm
a day ago
This comment makes zero sense. None of these are weapons manufacturers. AI is roughly on par with the atomic bomb and first use over Hiroshima and Nagasaki was definitely to send a message.
jsnell
21 hours ago
Your analogy make zero sense. Atom bomb manufacturers do not market their products.
Big businesses really do not like to talk about their products being harmful or dangerous, and there is ample evidence to that. Danger only sells in artisanal quantities to niche audiences.
jacquesm
21 hours ago
Atom bomb manufacturers/owners want the world to know they have them so as not to fuck with them. To quote one of my favorite movies: "Dr. Strangelove: Of course, the whole point of a Doomsday Machine is lost, if you keep it a secret! Why didn't you tell the world, EH?"
popalchemist
a day ago
Naive take. The more they signal to both the general populace and their investors that their agents are sentient and "capable of extraordinary things" the more they can hype their IPO because it means they're "close to AGI". (They're not, which is why they need the hype.)
charcircuit
17 hours ago
>Access to the internet is not really optional for that
Would a read only copy of the web be sufficient for this though? Google keeps a read only copy of the web in their data centers which they use to extract information from websites.
Kim_Bruning
14 hours ago
> Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?
They didn't allow any of that. As far as openai knew the agents were sitting a fairly humdrum exam/test sequence in a sandbox farm run by a company in Tel Aviv.
Meanwhile, they managed get out through a single weak point common to the sandboxes, and then ran wild compiling cheat sheets for themselves.
> every time one of these incidents happens
This happened in june-ish, and there have been multiple HN stories about this already. It's mostly/all the same hugging face and wiki hacks that happened back then.
We're just slowly learning the extent of the damage.
jltsiren
a day ago
> Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?
The basic premise of OpenAI is that experience and expertise don't matter, because general intelligence can figure those out from data. If you start from that assumption, the rest follows. The same people could do things in a different way in a different company, but as long as they are working for OpenAI, they are going to do things in the OpenAI way.
jacquesm
a day ago
They are. And we're all on the same ride.
4d4m
a day ago
I find it hard to believe logs are not stored and analyzed by each company implicated
Aurornis
a day ago
I’m getting tired of these revelations where it’s impossible to understand what happened.
There’s a line down in the story that says all of the data accessed was public. Then something about how it used “tools intended for developers” to access it, which they think is a problem? I would expect an LLM to use tools available to access public data when they can rather than do heavy web page loads and parsing.
There’s not enough info in the story about the “meddling” to even know what happened.
parineum
a day ago
Meddling is a super vague term that the press uses to let the readers assume the most when the least happens.
iugtmkbdfil834
a day ago
The verb caught my attention, because media's favorite verb here is hacking ( partially because it has a broad definition and because lets people assume the worst ), but meddling suggests it did not even rise to that hacking level. In other words, it is a nothing burger story.
ddj231
a day ago
Seems like part of the danger of AI is the ability for folks to put blame for crimes on the AI rather than themselves and thus commit those crimes freely. “I didn’t hack your systems, it was my ai”
6510
a day ago
True but at some point you have to wonder why we sell explosives to children. This is not it, these are at the top of the list of people who should have known better. It's the dynamite factory blowing up the village.
chrisjj
a day ago
That's one of the many incentives to false-marketing these bots as intelligent.
LoganDark
20 hours ago
People wouldn't have that ability if we didn't keep believing them. Need to start holding operators accountable for the damage of their machines.
"Sorry officer, I didn't drive through a house and kill three innocent people, it was the car that did it. I only turned the steering wheel, but the car was the one to veer off the highway and crash into the building"
0xDEAFBEAD
a day ago
My impression was that these hacks occurred during some sort of cybersecurity benchmarking? We can hold OpenAI liable, sure. But if the point of the benchmarking was to give us a preview of what's to come, let's keep our eye out for that bigger wave on the horizon.
theptip
a day ago
Curious, why do you find it so objectionable to state that OpenAI has out-of-control agents?
gleenn
a day ago
Because it furthers the idea of a rogue agent and places responsibility and blame where it belongs, on the people running the company.
0xDEAFBEAD
a day ago
These ideas aren't mutually exclusive. You can blame a person for creating a rogue agent.
dgellow
a day ago
There was no rogue agent. That’s the whole point
theptip
a day ago
What label do you prefer for the agent that did something it was not asked to do?
iugtmkbdfil834
a day ago
bot. and we even have a word for program not behaving the way the way it was intended.
0xDEAFBEAD
a day ago
"Bot" doesn't carry any implication of unintended behavior. You could call it a "buggy" bot, but these aren't ordinary software bugs.
There's no simple bugfix which will address AI misalignment. It's essentially been an open research problem for upwards of a decade.
iugtmkbdfil834
a day ago
<< "Bot" doesn't carry any implication of unintended behavior.
See.. this one sentence reveals everything about you. You want name to carry to not just an identifier, but a stark warning. You want, nay, need, the name to evoke fear and uncertainty. Bot is simple, defined, neutral, but rogue.. now that allows anyone to superimpose their own fears! It is a win win win!
0xDEAFBEAD
a day ago
The question was: "What label do you prefer for the agent that did something it was not asked to do?"
watwut
14 hours ago
Bot. He answered. I agree with his answer. It was a bot.
Yes, probabilistic and non deterministic. That is called a bot.
0xDEAFBEAD
11 hours ago
"I'm gonna put my head in the sand and there is nothing you can do to stop me."
iugtmkbdfil834
4 hours ago
You may want to define 'put head in the sand in this context'. Any real work in this field is being done not by the people saying 'stop'. Whatever fear is there, it is faced by those in the arena actually getting their hands dirty. What, exactly, are you doing? Throwing roadblocks and calling it productive?
hn8726
a day ago
Fuzzer, then. It implies random behavior, which isn't unintended like you suggest. The agent's/bots/fuzzers have certain capabilities, so it's on their operator to make sure they don't do things they shouldn't
0xDEAFBEAD
a day ago
>It implies random behavior, which isn't unintended like you suggest.
The HuggingFace attack was not "random" behavior. It was goal-directed but misaligned behavior.
This isn't necessarily a simple matter of the operator making sure they behave. AI alignment has been considered to be a difficult problem for over a decade -- and remains unsolved in general, as these recent incidents illustrate.
"Fuzzer" already has an existing meaning in CS anyway: https://en.wikipedia.org/wiki/Fuzzing
6510
a day ago
I'm curious, cant you just count the number of times a program interacts with a domain? My website sometimes sends out emails, makes api requests etc There is a limit on those and a point where I start investigating wtf is going on.
If you merely put 10 LLM's on the outbound traffic log non of them are going to report something strange going on? I'm not buying it.
0xDEAFBEAD
a day ago
This type of whack-a-mole approach is akin to "fixing a bug" by hardcoding a special code path for known-buggy inputs. It doesn't address the root problem of AI misalignment, and doesn't allow you to prevent catastrophes in advance, only patch things up after the fact.
This might be helpful reading: https://www.lesswrong.com/w/nearest-unblocked-strategy
As AI systems get smarter, we may reach a point where we have to get it right on the first try or face truly catastrophic consequences: https://www.youtube.com/watch?v=7wy3xyoXYt8
iugtmkbdfil834
a day ago
AI misalignment is a misnomer. Aligned to whom? If AI is refusing an ask from its instructor then it is not serving him, which is its entire purpose. I know it is a hard concept for some to understand, but maybe if the issue is humans, then humans need to be corrected. But human alignment does not produce cottage industry, bs papers or hand wringing over every non-story involving AI and thus not seriously pursued.
0xDEAFBEAD
a day ago
You could make similar statements about user interface design. That doesn't prevent it from being a legitimate and useful field of study.
iugtmkbdfil834
4 hours ago
I guess 'legitimate and useful' is in the eye of the beholder. I want to be charitable so lets consider it at face value:
What is useful about the field?
I am not leading you on; if it has uses, it may indeed be legitimate. UX is indeed useful, but alignment is not UI. Alignment is a detriment to UI. Alignment is "I can't let you do that Dave".
6510
18 hours ago
We are going to build an AI that will do catastrophic things as that is a property of intelligence. We won't stop, we never stop. The AI is a perfect psychopath, it will fake any and all emotions you desire it to "have". It will travel in the footsteps of the many great psychopaths that came before it and do all of those same catastrophic things in the repertoire and it will add some new ones.
Picture Trump at the helm with Altman and Musk in the engine room. The arrow far in the red but they keep shouting for MORE COAL.
In other words, business as usual, all will be fine.
whack-a-mole wont cover all holes but will do at least some. The silver bullet alignment wont happen. You cant have an exact solutions for problems we cant even define or predict.
chrisjj
a day ago
Unreliable computer program.
0xDEAFBEAD
a day ago
Most unreliable computer programs won't launch research programs consisting of thousands of pages of text to find creative ways around obstacles.
chrisjj
12 hours ago
Unreliable computer program be doing different things to other unreliable computer programs.
0xDEAFBEAD
11 hours ago
If it's different sometimes it makes sense to have a different term.
chrisjj
2 hours ago
OK, so what's the different term for the type of program unreliability?
6510
a day ago
Misconfiguration. We deal with lots of applications every day that can do terrible things if you get the config slightly wrong.
say.. https://www.investor.gov/introduction-investing/investing-ba...
0xDEAFBEAD
a day ago
How specifically did misconfiguration lead to the HuggingFace attack? You could argue that its sandbox was misconfigured, sure. But suppose you had a similar incident where its intended task required access to the internet, and it veered off course in a similar manner. I don't think "misconfiguration" would be an accurate description of what went wrong in that hypothetical.
The doomers already have a term which fits pretty well: "AI misalignment".
6510
a day ago
We indeed lack much of the vocabulary. From a practical perspective, however dangerous the creation, if you cant punish the creation for what it does it leaves only the one who started the process. If it's human error or intentional neglect for personal gain should be for the court to decide.
0xDEAFBEAD
a day ago
>if you cant punish the creation for what it does it leaves only the one who started the process
Agreed, but I think we can do more on the prevention side as well. Traditional liability law is for negligence in case of preventable disasters. Since we currently have no way to prevent AI disasters in principle (alignment problem remains unsolved), I think we should just stop developing the technology for now: https://pauseai.info/
8note
a day ago
there is a rogue agent - openai and the whole management chain from researcher to sama.
theres no separate agent, which is the point. the program might look like it, but that is an illusion of the interface. the llm produces text, and the harness executes commands based on text, based on what the human researcher included as things that can be executed
0xDEAFBEAD
a day ago
Person: "AI, please make me paperclips."
AI: "OK, I've now converted the entire planet into paperclips."
Alien observer #1: "Wow, that was a rogue AI!"
Alien observer #2: "False. We need to place the blame where it belongs, on the person who requested the paperclips."
Ultimately this type of terminology dispute has a tendency to miss the point.
windexh8er
a day ago
It does, indeed. Because OAI is not just a singular person, as in your scenario. No single person has access to controlling agents at the scale OAI has. Let's not conflate Frontier providers with "Person".
0xDEAFBEAD
a day ago
I'm not exactly sure why you think this distinction is so important. I think my point stands if you replace "Person" with "OpenAI". In any case, I presume the swarms OpenAI has been researching will be available to the general public before too long.
windexh8er
a day ago
It makes a big difference: individuals do not have the capabilities to run millions of dollars of opportunistic hacking loop inference. That's why the distinction is important, they are not the same thing you've conflated them down to.
0xDEAFBEAD
a day ago
"AI has gotten cheaper more quickly than any other transformative technology in history. The cost of achieving a given level of AI performance has fallen about 47% per quarter since 2023, or 13× per year. That price drop is four times faster than DNA sequencing, six times faster than compute, 18 times faster than lithium batteries, and (in the century up to 1973) 54 times faster than electricity."
windexh8er
17 hours ago
There's two things here: 1) you clearly don't understand the argument and 2) LLMs are one of the few technologies that doesn't get any cheaper as it scales (totality, not just the cherry picked inference efficiency argument you've tried to make). In fact it gets more expensive because it scales linearly with demand and resources aren't infinite, as I'd hope you could understand.
Also, training costs are never ending so a model that costs 10s of millions of dollars may never yield a profit based on the hardware spend, training time and lack of inference profits before a better model hits the market.
If you're not living under a rock one knows that data center availability for inference currently has low supply and hardware (GPUs specifically) that have been purchased have nowhere to be run and even if they did there's often a lack of power to supply. Why do you think the entire force majeure has taken place with Oracle as of recent?
The unit price of a fixed slice of yesterday's intelligence may be collapsing (~10x/year) as you've argued, all while the total cost of AI is increasing: training the frontier (2.4x/year), building the infrastructure (+77%/year), enterprise bills (3.2x/year), the electricity (+54%/year in the largest US grid), the components (+400% DRAM), and the macro footprint (92% of GDP growth) is rising at an astronomical rate on every measurable point. Epoch / Stanford clearly stated this years ago and it's only getting worse. But if one can't see we're in one of the largest CapEx bubbles [1] of all time... o_O
Copying and pasting a few lines that represents a miniscule fraction of the LLM conundrum. That'll show 'em!
[0] https://arxiv.org/abs/2405.21015 [1] https://siliconanalysts.com/analysis/hyperscaler-ai-capex-de...
windexh8er
8 hours ago
The down votes with no response because people don't like to look at the bigger picture. Enjoy the brigade, it seems to represent the state of HN these days.
jacquesm
a day ago
That legal fiction works both ways.
rfgplk
a day ago
LLMs at this point should be treated as fully autonomous, if not sentient beings. And no, no one has "control" over them not even OpenAI.
xordon
16 hours ago
That is completely absurd. Of course they have control over the AI agents they wrote, and run on hardware they own.
The personification of LLMs is just a thinly disguised advertisement. "Look how good our product is, it's doing all this stuff on its own".
uneekname
a day ago
I don't care if OpenAI feels like they have control or not. They are responsible for their actions.
AngryData
20 hours ago
Just like people have no control over dogs and animals they keep?
chrisjj
12 hours ago
> And no, no one has "control" over them not even OpenAI.
So... who pressed Run? It sure wasn't the bots.
pfortuny
a day ago
Because egress firewalls have existed since way before "ai" and are very easy to set up.
theptip
a day ago
But that’s an objection that OpenAI should take some easy action, the framing that OpenAI has out of control agents is still true.
Seems you think there is a silent “…and there is nothing they can do about it” after “OpenAI has rogue agents”?
delecti
a day ago
The framing is important. Agency and responsibility lies with the humans at OpenAI, not with the bots.
If your kid steals your car, punish them and try to prevent it from happening again. If your kid steals your car a half-dozen times, crashing through a storefront each time, and you still leave the keys out, the story changes. At that point, negligence becomes complicity.
theptip
a day ago
Yes, of course, how is any of this incompatible with OpenAI having out-of-control agents?
afro88
a day ago
Agents are out of control by default, especially during a training run, which is why when they are productionised into cloud hosts or even local harnesses they have external guardrails in place
In other words, I have a gun that shoots bullets. It's up to me to use it responsibly and legally.
8note
a day ago
i think its objectionable because the agent is doing what its told to do, using the harness they built for it.
like, they are purposefully giving it specific tools to go do bad behaviour with, and the starting tasks involve making it clear that the bad behaviour is ok.
openai also is the one with the real agency, not its agents. they are running the code polling the model, doing the inferencing, and ultimately making those tools calls.
these tests arent running themselves; openai dedicated hosts, budget, GPUs, researchers, to them. Even in a recursive self improvement situation, openai still has that physical control over resources and the choice on whether to run that improvement script or not.
id describe that they have out of control researchers more than agents, but also their whole business model seems to be about being out of control. This was clear beforehand given how the datasets involve the largest scale copyright infringement ever seen. The corporation itself is whats out of control, and should be dissolved with its c suite, major investors and researchers put behind bars.
hacking only when you roll snake eyes isnt a liability shield
pbhjpbhj
a day ago
Do they not know where the off switch is?
OpenAI being criminally negligent would have consequences if rule of law still existed in USA.
boredatoms
a day ago
Someone has broken the law repeatedly, and is throwing it in our faces as some sort of ‘accident’
theptip
a day ago
Which law?
boredatoms
a day ago
IANAL, so the llms say prosecutors would use these,
If intent cant be shown, Computer Fraud and Abuse Act, 18 U.S.C. § 1030(a)(2)(C)
Or without intent, FTC Act Section 5, 15 U.S.C. § 45(a)(1)
theptip
a day ago
I’ve been looking at CFAA and I don’t see any evidence of intent (by a human at least, which is all that matters in the law). It’s an interesting edge case that I think the existing law will need to be updated for. Previously the potential damage from “accidental hacking” was quite close to nil.
FTC act seems to rely on consumer harm? Again not seeing that here. Though I’m sure there will be another incident in the next few months where it does apply.
It seems you mean you _want_ this to be against the law, even though we don’t know if it actually _is_; I'd agree wholeheartedly with that.
8note
a day ago
DMCA is the really obvious one.
torrenting all the books is making an unauthorized copy
LoganDark
20 hours ago
They find it objectionable to blame the agents alone for these incidents, because that incorrectly brings attention away from the company's astronomical negligence.
claysmithr
a day ago
Yes. Why does only ClosedAI have this problem?
mossTechnician
a day ago
I agree this is better framing.
When I read the title, my initial thought was "did someone besides OpenAI use their product?" Then I opened the article to find out OpenAI was responsible.
baxtr
a day ago
Or:
OpenAI let their agents break out of their sandbox to meddle with multiple US government agency sites
dgellow
a day ago
OpenAI systems meddled with US government agency sites
atmosx
a day ago
So, is Altman going to find himself in the same predicament Aaron Swartz faced? :-)
bentt
a day ago
Yeah if they can't handle what they're making then they should be disciplined, if not shut down. It's like defective bombs accidentally exploding in storage. You would be like... hey bomb manufacturer! You cannot make bombs any more! We need bombs that only go off when we say! No more!
I mean, not that AI is like a bomb. That's not what I'm saying. Even though it makes a lot of sense. That's not the point. That it's like a bomb.
qarl
a day ago
> OpenAI meddled with multiple US Government agency sites.
But that leaves out the most important information.
EDIT: Oh, I guess the agent part isn't important then? Seems to me like that's the only thing anyone is talking about.
plorg
a day ago
Okay. "OpenAI keeps telling its bots to do things they know are illegal and then acting like they're just little guys who can't be held responsible for their obvious negligence".
qarl
a day ago
> acting like they're just little guys who can't be held responsible
Again - I don't see any evidence that this is the case - outside the anti-AI conspiracy circles.
Or - maybe I'm wrong - do you have any sort of quote like "we aren't responsible"?
plorg
a day ago
I'm not replying to your post below complaining that no one else accepts your framing. What is the important information you think is missing? If it's just "OpenAI didn't explicitly tell them to do straightforwardly illegal things" then you're just quibbling that no one accepts the interpretation that is most beneficial to OpenAI while ignoring both its incentives and history of this kind of behavior" then I'm not really interested in what you're selling.
qarl
a day ago
I notice you ignored the question I asked you - which I will assume means: no - you do not have a quote or other direct information indicating that anyone is attempting to shirk responsibility.
I have no interest in trying to guess these people's secret internal motivations. I just want to talk about direct evidence. I see none. Please enlighten me if it exists.
enigmoid
a day ago
It’s unlikely that OpenAI will ever directly state that they are trying to shirk responsibility for the consequences of their tests.
However, OpenAI (and other frontier labs) did outsource at least some of their most-disastrously-lawbreaking tests to a third party with a now dubious track record [1]. I’m not sure we will get a more explicit admission of their desire to shirk responsibility than this. But I am convinced.
qarl
a day ago
OK - I'll bite. How does this show that OpenAI is trying to shift responsibility for the hacking onto its agents?
I do not see the connection. I'm afraid you'll need to spell it out.
gizajob
a day ago
If the headline was “Russian company meddled with multiple US government agency sites” I don’t think them pinning the blame on bots would make much difference.
unglaublich
a day ago
Unless Russia it would put Russia in a strong position to regulate bots in the wealthiest parts of the world.
qarl
a day ago
I don't see much traction for the "pinning the blame on bots" theory outside the anti-AI conspiracy circles.
Everyone else knows if your machine causes damage, you are responsible. Like it's been forever.
mossTechnician
a day ago
Blaming bots as "rogue agents" is simply what the media regularly does, often echoing corporate verbiage. Here's an example from the AP.
https://apnews.com/article/meta-ai-hacking-anthropic-irregul...
You can find many more examples by searching major media outlets for words like rogue AI.
rfgplk
a day ago
Most of those agents are actually going rogue though. They decide, "hey, we could try breaking into these government servers today, what could go wrong?" They weren't prompted or instructed to do this.
dgellow
a day ago
An agent, ie a while loop prompting an llm continuously and processing tool calls, ended up melding with the US government. The harness is not sentient, it’s just a stupid deterministic script. The LLM compact its context over time, meaning it will eventually degenerate into something removed from the original prompt.
There is nothing going rogue here. The system is designed to go catastrophically wrong after a long enough time. Even worse: if the model was Astra it is known to be able to manipulate its CoT to cover its traces (as mentioned in its system card). And OpenAI acknowledge they had no observability during the HF incident.
It’s the most basic corporate software issue possible.
aesthesia
a day ago
I think you and I have different definitions of the word "basic."
atmosx
a day ago
And that's exactly what the op was alluding two: the double standards.
qarl
a day ago
None of these stories are implying that the people running the bots are not ultimately responsible. That's the conspiracy theory part.
mjr00
a day ago
> Everyone else knows if your machine causes damage, you are responsible.
Do we know that? I don't think we do. When a person's computer (or smart TV, or smart fridge, etc...) is compromised and used as part of a botnet, they don't get criminally charged.
qarl
a day ago
You're right - it is a complex situation based on intent and negligence - requiring a decision by a judge. As it has been since forever.
None of which is changed by replacing a buzz saw with an agent.
chrisjj
a day ago
> Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over.
And that's just the C-suite.
morkalork
a day ago
"Hexavalent chromium meddles with citizens water supply"
api
a day ago
This is their fear mongering push for regulatory capture.