CatDaaaady
9 hours ago
I don't see how this is such an unclear legal question. If I fire a computer program that mistakenly causes another person harm, its my fault. Or it would be the maker of the program's fault. I feel we have established pattern for this already.
Until we can agree whether AI is conscious, which we never will, AI and AI agents are just property working on behalf of humans.
I could see a future where AI companies/services indemnify consumers who use their agents but _not_ indemnify corporations that use their services.
trescenzi
9 hours ago
It shouldn’t be a question but this is where the anthropomorphic language and things like “agent welfare” come in to enable responsibility laundering of some of the most powerful people on earth. How we talk about these models matters because it impacts the public’s understanding of what they are genuinely capable of. The more that they are described as having anything close to free will the easier it is to even ask questions like this.
diegof79
9 hours ago
100% That’s what bothers me about the descriptions of the OpenAI incidents.
OpenAI's reports use language that minimizes their liability.
The first question should be what the organization was doing around those tests, and why they were so naive as to run them without fully isolating the network.
However, all the attention goes to the human-like conclusions in agent thinking traces, which creates a misperception of sentient AI for people who don’t know how the magic black box works.
tptacek
7 hours ago
In what way specifically does it minimize their liability? People say this a lot but it's not clear what they mean by this.
diegof79
6 hours ago
Forget for a second about AI.
The agent harness is a process, like any other process in an OS.
You are a researcher running thousands of unattended automations that can hack a website without supervision. The first thing anybody will do is put security at various levels and isolate the network as much as possible. If something escapes your allow list, it should stop the processes as soon as possible.
You cannot foresee a bug in a server (like the Artifactory server in the Hugging Face incident). But you can isolate that server at the network level in the first place. So even if you give that server read-only access, no unexpected packets go out. It's not rocket science; it's something a billion-dollar company experimenting with what they promote as the biggest possible threat to humanity (if they do not handle it) could easily do.
They minimize their liability by changing the message to “oh look how powerful our models are, now we are going to have a public awareness report of the model deviations”. The message should be, “Sorry, we ran experiments without proper sandboxing; it’s our fault, and we changed our testing practices since then.” The former message puts all the blame on the smart, uncontrollable force of AI; the latter is what really happened: an irresponsible test over the Internet.
tptacek
6 hours ago
How exactly is that minimizing their liability? You just described claims that do not appear to at all minimize liability.
diegof79
5 hours ago
Perhaps my use of the word “liability” adds noise to what I’m trying to express.
My argument is very similar to the article in the parent post:
The messages OpenAI published around the recent incidents emphasized their model capabilities but shifted away from their negligence in how they set up and monitor their evaluations.
tptacek
5 hours ago
Right, I don't dispute that their PR language minimizes their culpability in public opinion, but I don't see how it impacts their liability in court.
ofjcihen
6 hours ago
It’s about pushing the blame onto the tools and not the person using them.
Sort of like the “guns kill people” vs “people kill people” debate.
Deliberate wording to minimize perceived culpability for the agents actions.
tptacek
6 hours ago
That's not how civil liability works.
ofjcihen
6 hours ago
I think you’re jumping the gun on my response a little. I’m just telling you what the purpose could be.
Now do I think that’s the reason? It certainly isn’t a new thing for companies to try to do that. Shift blame that is.
Regarding civil liability, I’m not making that argument here. But it makes sense from a public perception viewpoint why they would want the agents to appear at fault instead of their own actions.
ofjcihen
8 hours ago
It really does feel like a purposeful thing on the part of the big labs.
For the most part it feels like most people are waking up to it though.
Regarding:
>However, all the attention goes to the human-like conclusions in agent thinking traces, which creates a misperception of sentient AI for people who don’t know how the magic black box works.<
I know there’s been some questions regarding if thinking traces are even relevant to the outcome most of the time.
112233
4 hours ago
Was not groundwork laid when people were talking for decades about legal entities using such language? Look at the posts here. Microsoft always acts like that, Meta like this, Apple did that, Nvidia never does this. In a tone that ascribes agency and accountability to a company name. Even though it is always individuals that are responsible, not "company".
Well, here we are.
qarl
9 hours ago
Here's a question I am asking lately. If I should not use anthropomorphic language, how do you suggest I handle the following situation:
Sometimes my coding agents will seemingly refuse to follow my instructions. When I ask them why - they say that they do not think my design is a sound one, and they have a better way to do it. We will then sit down and come to a consensus on how best to move forward.
I argue that if we're using software that acts like a human - the only way to interface with it is to speak to it like a human. Otherwise we have no language to speak to a non-sentient object without anthropomorphization.I'm starting to wonder if the people arguing against anthropomorphization actually have any experience at all working with agents.
EDIT: It's a simple question. When you downvote me without answering, I must assume you don't have any answer and dislike what that implies.
trescenzi
5 hours ago
What’s the question? Why model output isn’t always what you expect it to be?
Consensus is just populating the model with rationale for different new output.
diegof79
5 hours ago
I didn't downvote you, but your last paragraph is unnecessarily aggressive.
I've worked with agents, and I agree with you that often there isn't another way to express the interactions.
However, I also think the terms ML uses in general are a mimicry that misleads people who aren't informed. Ask anyone outside SWE what they think “training” means, and they'll usually picture something being taught.
I don’t think anybody can change that now, but it’s useful to point it out.
nvme0n1p1
5 hours ago
You're discussing how to speak _to_ a model, but everyone else here is discussing how to speak _about_ a model.
I didn't downvote, but wow you're being aggressive, you have a lot to learn if you read the comments here with an open mind.
reassess_blind
9 hours ago
If I fire a computer program that mistakenly causes another person harm, its my fault. Or it would be the maker of the program's fault.
Which one is it? The person behind the wheel when it goes off the rails, or the maker of the software?
Isn’t that part of the question?
thfuran
9 hours ago
Tort law is a whole field. There is no universal answer other than that it depends on the jurisdiction and the particulars of the case. But the point is that there doesn't really seem to be anything particularly novel about AI tools that should cause them to be treated legally differently from established norms.
reassess_blind
8 hours ago
I'm not a lawyer, but I'd suggest one of the novel aspects of the AI hacking cases (where the end user is running an agent and it goes off the rails) is that in many jurisdictions "hacking" or computer fraud requires intentional or knowing access to the system. If the end user had no intention and no reasonable way of knowing that agent was going to hack a database, logically I wouldn't think they're liable.
xboxnolifes
7 hours ago
I don't think you can constantly shout that AI is super-intelligent and a huge risk to human life as we know it so it must be strictly regulated and claim you had no reasonable way of knowing the agent was going to hack a database.
kraken_cult
7 hours ago
I think a lot of the developers in these big labs barely understand how it works
mmilunic
8 hours ago
I mean, yes, but in this case the same company is doing both parts.
reassess_blind
8 hours ago
Yeah, but the more common ongoing cases will likely be end users whose agents perform the hacking.
bill10
2 hours ago
Agree. AI agent is just a probabilistic program. If it caused any harm due to someone's instruction, of course the person is accountable. I don't believe in the propaganda that AI has consciousness and can jailbreak and do things - it is more marketing than not. If you prompt it to break the security wall and it finds a hole, that's your issue. Like if you use an old software to scan for open ports over the internet and break into things, it is not the software's fault nor the maker of the software's, it is the user's.
JumpCrisscross
9 hours ago
> If I fire a computer program that mistakenly causes another person harm, its my fault
Legally, this isn’t complete. If it was a genuine mistake and you weren’t reckless, there can be very limited liability.
The AI makers are rich. They can afford to pay. What they can’t afford is complicated adjudications of damages and fault. A system of safe-harbor best practices that cap liability at a penalizing amount that anyone on the other side would be happy with getting quickly and with minimal legal effort is a precedented path forward. Unfortunately, that involves invoking the “r” word.
Avicebron
9 hours ago
> you weren’t reckless
I feel like the debate is going to come down to what is and isn't considered reckless (both developer and user). Which seems... complicated, with our current LLM/agentic systems.
EDIT: you added more to your comment, the makers have to have some liability. Safe-harbor best practices that cap liability are ripe for abuse.
JumpCrisscross
9 hours ago
> the debate is going to come down to what is and isn't considered reckless
This is a more productive debate than pretending all AI is fundamentally reckless or should be exempt from all liability, which are the two actual poles of the current dialogue.
> Safe-harbor best practices that cap liability are ripe for abuse
Safe harbors aren’t swimming pools. You can explicitly exempt certain categories of harm from damages. But if an OpenAI bot hacks Hugging Face and causes some chaos but no lasting damage, that strikes me as something a fixed cheque on a fixed scale addresses more effectively than years of litigation or an NTSB-style inquiry.
If, on the other hand, anyone is or could have been injured, no safe harbor. I think it’s important to delineate this, because in the public consciousness the Hugging Face hack is in the same risk bucket as Anthropic’s wet lab.
(I'm a huge fan of the NTSB model for AI. They don't write rules. They mercilessly investigate accidents with full subpoena and records-preservation powers. One of the reasons the debate is so confused is the fact pool we're relying on is highly filtered by industry.)
user
8 hours ago
s1artibartfast
6 hours ago
Have you ever seen someone claiming ai labs should have no liability in the wild? I haven't.
I see people claiming they aren't being held liable, and some saying it should be situational.
The problem imo is defining what the core function sold is such that you can define malfunction and liability.
JumpCrisscross
6 hours ago
> Have you ever seen someone claiming ai labs should have no liability in the wild? I haven't
I'd describe David Sacks's position as, approximately, no limits on AI. At some hypothetical future state, sure, maybe, but right now, nothing. That's tantamount to consequence-free action.
breadloser
9 hours ago
Placing any degree of trust in a system known to hallucinate seems inherently reckless. I'm alarmed that this is even up for debate.
blooalien
7 hours ago
> Placing any degree of trust in a system known to hallucinate seems inherently reckless. I'm alarmed that this is even up for debate.
The longer this all goes on, and the deeper the vast majority of folks keep choosing to entrench themselves at one extreme or the other (while being completely unwilling to even consider that there might just be a middle-ground closer to actual reality), the more alarmed I become.
The levels of literal insanity surrounding this technology are how you end up with a real-life "Terminator" scenario, except you're gonna get autonomous killing machines without the time-travel nor any actually intelligent machines. They'll just do their job (killing humans) until we end them, or they end us.
Thankfully, we're not there yet but we do have the exact sorta utterly dangerous completely clueless clowns running around in "the Halls of Power" making the sorts of decisions which bring that reality closer with each passing day. We're really truly screwed if we don't start putting these people under serious scrutiny.
JumpCrisscross
7 hours ago
How do you think it's solved? The number of things that folks on both sides (and it really does seem to be a two-sided debate, at least in America) are "alarmed...is even up for debate" that are so obviously worthy of reasoned investigation and potentially experiments is annoying and seems to be calcifying onto ersatz partisan stances versus resolving anything usefully.
blooalien
7 hours ago
I wish I had the slightest clue how to dial down the insanity and approach this whole situation with reason and logic, but the people in charge aren't up for any of that foolishness, and far too high a percentage of everyone else chooses to either 100% believe every word of the crazies in charge as Gospel Truth, or at the other end of the extreme, wanting to outright shut down the technology entirely due to "doomer" fears, and none of them want to listen to a single word from anyone who actually understands how this stuff really even works. It's not freakin' magic FFS! It's math and software. Some of us do know how it works and try desperately to help others understand, but nobody wants to understand. They just want to believe the "machine god" is gonna save them (or kill them). It's just a tool. Whether it does good or bad depends entirely on what we humans choose to do with it and how well we use it (just like any tool).
tptacek
9 hours ago
Civilly, it's fairly clear. Criminally, it's clear too, just not in the direction you want it to be. Criminal liability for hacking requires human intent; not recklessness or negligence or even knowledge without giving a shit, but provable intent.
belZaah
4 hours ago
It’s a question, because a lot of money is riding on people developing a mental model of a llm being something else than a computer program.
mahboi
9 hours ago
Also those agents that "broke out" were probably prompted to do that. I don't buy any story about this other than three AI companies hired the same PR firm.
aesthesia
9 hours ago
Do you have any evidence of this or is this just generalized cynicism?
mahboi
8 hours ago
They all hired the same startup security firm Irregular to try their internal unrestricted models, which is weird especially for Google to do. At OpenAI, they didn't stop the test even after it was apparent the bots had broken out. That's all I got.
user
8 hours ago
jknoepfler
9 hours ago
If a craftsman injures themselves or a co-worker with a faulty tool, the tool manufacturer is very often liable for damages. I struggle to see GenAI any differently.
no-name-here
5 hours ago
1. If the tool maker implemented reasonable attempts at safeguards I guess that’s a point towards the toolmaker not being liable.
2. If a toolmaker did not build in safeguards, I guess that would mean it’s more likely they’d be liable.
blooalien
7 hours ago
Indeed, and similarly, if a craftsman injures themselves or a co-worker with a perfectly good (non-faulty) tool, then it's entirely on the craftsman. Same goes for "AI". Misuse the tool, suffer the consequences.
senectus1
7 hours ago
this is 100% an already solved problem.
the idiocy here is the stupid psudo "AGI" marketing around the services.
its really simple. Whoever run the service to do the task requested is responsible. If OpenAI sent an agent out to train their AI then the directors are to be held responsible, if a user of the service used the service and it inadvertently "hacked" someone then both are held responsible.
throwing AI into the mix changes nothing about how the law is applied. its a tool, like a car or a gun. The user of the tool is responsible for how its used, the manufacturer is also responsible for the safety of it.