bluegatty
9 hours ago
"OpenAI models attack websites and take anything they can out of them because that is the business model of the company."
No, good gosh let's stop with the hyperbole.
The models were given instructions to get answers by any means in a loose test harness, not to steal stuff, moreover, they're not 'learning from OAI staff'.
If we are cynical, we could say the 'lax security was on purposes - hoping for a big media event'.
And OpenAI is 100% responsible for the actions of their Agents - but lets' not overstate or conflate what is gong on.
afry1
8 hours ago
This is a misreading of that pull quote.
They're not "learning from the OAI staff", but lawbreaking and disregard for regulation is absolutely at the heart of OpenAI. And the activities that this company takes (or doesn't take) directly influences what the models do (or don't do).
The fish rots from the head down. Models don't learn, but I find "OpenAI models attack websites and take anything they can out of them because that is the business model of the company" completely correct.
The rest of the paragraph from the article:
> We do not have to get too deep into the nature-vs.-nurture argument to suspect that OpenAI executives’ cavalier attitude regarding the taking of information that is not theirs has filtered down to their researchers and the products they create. You don’t have to stretch to paint this picture: OpenAI models are attacking websites and taking anything they can out of them because that is the business model of the company.
GTP
8 hours ago
I'm not convinced about this. In the article, they also say that they could feed the model with copyright law like that would fix the issue. Unfortunately, not only the LLMs have already been trained on law taxtbooks and codes, but we also have examples of people on the internet were models disregard precise instructions only to apologize later.
Note that this is not to be seen as an excuse for OpenAI to avoid responsibility, just like parents are responsible for damages caused by their kids.
jdiff
8 hours ago
Everything goes into the training data. What is prioritized and what behavior is targeted out of that data is something that comes from OpenAI.
GTP
8 hours ago
True, but we saw alignment issues also on topics that aren't part of OpenAI's business model or business conduct. Like an agent tasked with solving build failures due to failing test cases deciding to "solve" the problem by deleting the failing tests.
pj_mukh
8 hours ago
"OpenAI models attack websites and take anything they can out of them because that is the business model of the company"
Wait, what did they hack and take into training data? On the whole, I totally buy that OAI is legally (and criminally) responsible for their agents, but surely, damages have to be proven?
bluegatty
8 hours ago
"but lawbreaking and disregard for regulation is absolutely at the heart of OpenAI. "
No it is not.
What laws and regulations are they breaking?
Their agents broke out of a harness and harassed some other sites, it's not good, but it's not specifically breaking laws. Other companies are treating it as accidental, it mostly is that.
You're rhetoric here is agitating, conflating. This is my point.
dspillett
7 hours ago
> and harassed some other sites, it's not good, but it's not specifically breaking laws
I'm sure it would be considered a breach of the UK's Computer Misuse Act, and there are no doubt statues elsewhere that are relevant too.
Once is an accident. Twice is incompetence. Three+ is, at best, pushing your luck to see what you can get away with.
bluegatty
7 hours ago
If they broke laws then they would be investigated.
And I totally support that.
But I don't think they did.
They could get sued, mind you.
ykonstant
7 hours ago
>If they broke laws then they would be investigated.
Ah, I love your optimism.
bluegatty
7 hours ago
Tell us what laws they broke.
The Australian government did an assessment and decided there was no 'intent' on the part of OpenAI and therefore no charges.
Where did they break any law?
anon48293
4 hours ago
s.478.1(1) Criminal Code—unauthorised access to, or modification of, restricted data;
s.474.17 Criminal Code—using a carriage service to menace, harass or cause offence
The AI knew it was doing this illegally. OpenAI is owner of the AI. Therefore they are liable.
IAmBroom
7 hours ago
> If they broke laws then they would be investigated.
Not a fact but a hope. Most lawbreaking is never investigated. It has to be discovered, the authorities have to be alerted, and then they have to choose to investigate. See the recent Cornell University gangrapes for proof that authorities can choose to simply not investigate.
> They could get sued, mind you.
If they didn't break laws, as you imply, the lawsuit should be tossed out as frivolous. (Spoiler: they did break laws.)
bluegatty
6 hours ago
"If they didn't break laws, as you imply, the lawsuit should be tossed out as frivolous. "
No, that's not how it works. Civil law is something completely different from criminal law.
IAmBroom
5 hours ago
Your claim is that you can be successfully sued without breaking a law. Cite.
Civil law is still based upon law.
bluegatty
5 hours ago
Stop depending on others to 'cite' because you have no understanding of basic civics and don't want to look things up.
Most of civil law is related to things like breach of contract - not breaking any laws.
Y_Y
4 hours ago
What about the contract law that says you can't (typically) breach contracts?
leereeves
4 hours ago
> See the recent Cornell University gangrapes for proof that authorities can choose to simply not investigate.
In the interest of accuracy, according to the DA, they did investigate in 2024 and did not prosecute because:
"Jane Doe’s sworn statement in November of 2024 did not allege that she was drugged against her will or gang raped. On the contrary, Jane Doe’s statement described her participation in drug use and sexual conduct as voluntary, conscious, and consensual."
https://www.tompkinscountyny.gov/News-articles/District-Atto...
esseph
7 hours ago
TheOtherHobbes
6 hours ago
The long list of laws and regulations that would have had a low-status individual jailed if caught.
If you don't believe me, try hacking some government sites and see what happens to you.
But OpenAI is a huge corporation and low-status laws don't apply.
Although to be fair the US has a number of prominent high status individuals who clearly belong in jail, so it's not as if Altman is getting uniquely personal treatment.
bluegatty
6 hours ago
Name the laws they broke.
gregw2
5 hours ago
I am not the earlier poster, but I believe copyright infringement at the heart of their business model is what is referred to.
If I download a bunch of music from a torrent without a license, even if I don't listen to it, I'm liable, but if OpenAI or other LLMs gets content by some other unlicensed means (Anna's Archive, t), they are somehow not liable for the copy they made however temporary (but not so temporary if they leave it around to train a second model)?
And/or derivative works? And/or contributory copyright infringement when they regurgitate that copyrighted text when given certain prompts?
I get there is some nuance to copyright law, (four prongs), some utility to the outcome, and some legal (but not plausible) deniability. But there is no way they have clean hands on the copyright front for at least some actions they have taken. If there were, it would be in all their marketing and they would be pushing regulators to bind their competitors, onshore or offshore, more tightly in this regard.
I was around when search engines took advantage of similar ambiguities in copyright that took many many years to get litigated for similar reasons.
danaris
2 hours ago
How about the CFAA?
Teever
5 hours ago
I'm not a lawyer but from my laymen perspective I see a whole lot of negligence and racketeering. Also the bribery with the American current administration.
These things may not be illegal in America but they certainly are illegal some jurisdiction that OpenAI and others operate in.
bsenftner
8 hours ago
What laws and regulations? IP theft, of published media, to the scale of "all of it". If it were music and film and not text, the music & film industries would have nuked Silicon Valley by now. Which shows the relative power of popular media versus text publishing.
RHSeeger
8 hours ago
> The models were given instructions to get answers by any means in a loose test harness, not to steal stuff, moreover, they're not 'learning from OAI staff'.
If you equip someone with the tools to do harm and then tell it to accomplish a goal "by any means necessary", especially someone you KNOW has no real concept of ethical behavior... then you are telling it that it is acceptable to steal, kill, or whatever else. I honestly cannot how it can be seen any other way.
If it was a crime boss telling their enforcer "by any means necessary", we would all know exactly what that means. And we should all know what it means here, too.
BoxOfRain
6 hours ago
Yeah I'd be shocked if there wasn't a degree of 'will no one rid me of this turbulent priest?' going on here.
orf
8 hours ago
> And we should all know what it means here, too.
It very clearly did not mean “go and hack third parties” though
bluegatty
7 hours ago
".. then you are telling it that it is acceptable to steal, kill, or whatever else. I honestly cannot how it can be seen any other way."
This is the hyperble I am referring to.
If you 'honestly can't see it any other way' then maybe consider stepping outside to think how to ground those thoughts a bit.
The AI is not obviously instructed to 'commit acts of violence' and it obviously has guidelines.
By 'whatever means' would imply, things like 'creative collaboration, using novel research, experiments' etc.
It was setup in a harness that was weak - I think it's fair to maybe question the strength of that harness, and the oversight, but that's a different question.
It was an agent that broke through some networking/containerization, it's not 'murder and violence on the streets' for gosh sakes.
"And we should all know what it means here, too."
No - this is a delusion, resulting from lack of context, and creative projection, and possibly a lack of exposure to real world business conditions.
It's fully appropriate to be cynical, but in a way that makes sense, and is consistent with reality.
This is a lab experiment that leaked, not some mafia activity.
christkv
9 hours ago
So why is OpenAI not charged with Cybercrimes. You would be if you did the same.
exitb
8 hours ago
It's not unusual for intent to play part in legal framing of an issue. I'm not very fond of the "cybercrime" angle, as it kind of lets them off the hook if they're able to prove a lack of intent. Meanwhile what we actually see is negligence.
Applejinx
6 hours ago
I've never seen anybody or anything go out, suck up everything in the world and distill it into a different thing containing elements of all the things they took for no particular reason with no expectation or intent.
That's a WILD angle for them to argue. Lotta energy being expended for a lack of intent. Lotta money spent…
exitb
5 hours ago
These are two different issues. Do they intend to create models that basically encapsulate entire human intellectual value? Yes, but that's apparently not illegal. Did the intend to hack Hugging Face? Probably not.
Findecanor
8 hours ago
From what I have learned, to charge someone for hacking the prosecutor has to show that the perpetrator had intent.
Unfortunately, gross negligence -- which you could argue to be the case here -- is often not enough, unless you could show that it has caused real harm.
From my perspective, it is only a matter of time before it is: and that's why there is need for better legislation covering what AI models do.
GTP
8 hours ago
This is a good question (unfortunately a good answer is given in the article), but it is orthogonal to the why LLMs are committing cyber crimes.
rcxdude
8 hours ago
That is not obviously true.
freecodeio
8 hours ago
just so you know, this is why they're not getting any legal pushback, the free, legal, "well acktually" commentary on the internet
if people called it out for what it is, a reckless negligent destruction of private property by a company, someone will feel the moral obligation to bring justice, if there's any to be found
rcxdude
8 hours ago
I highly doubt the legal system is browsing social media to make their decisions. It is worth calling out, but it should be called out accurately (and that might also help understand why the legal system is making the decisions that it is).
bamboozled
8 hours ago
Go do it yourself.
Start a company, get a bunch of agents to hack a bunch of stuff, say you were "just training the models", let us know how you get on?
rcxdude
8 hours ago
If all evidence suggests that it is at most due to negligence, you could expect the same results.
bamboozled
5 hours ago
I think you'd get the same results if you play golf with the right people?
plastic-enjoyer
9 hours ago
Aren't these capabilities trained into the models by RL on cybersecurity benchmarks?
bluegatty
9 hours ago
The 'capabilities' are more around creative problem solving. The notion of legality, property, propriety - those are second order issues.
They are not making models to be evil.
They are making them to be relatively autonomous though, and 'identity centric' as opposed to just making them 'policy machines'.
Altman and Dario are not evil or even jerks really. They are 'talking really big' and there might be some sketchy underhanded things but I think relatively minor.
Also - given how powerfully bad AI can be, this could be 100x worse.
I think most other companies would have weaponized the AI a long time ago for competitive use etc..
OAI and Anthropic are private companies, projecting narratives way out of proportion but they are not evil, at least not yet.
Jensen, Dario, Altman in similar category. Not like Musk. And a bit different than Sudar or Satya who are more polite board-approved corporate creatures.
RHSeeger
8 hours ago
> They are not making models to be evil
There are multiple ways to read this
1. They are not making models with the intent that those models act in ways that are evil
2. They are not making models with the intent that those models act in ways that are evil - But the way they are making the models results in the models acting in ways that are evil
3. They want to act evilly and making the models is a way to do that
4. The way they are making the models is an act of evil (this isn't an interpretation of the sentence, just kind of closing the grouping of situations)
I would argue that
- 1 & 3 are very likely not true
- 2 & 4 are entirely reasonable interpretations of the situation
If you act in a way to bring benefit to yourself with the result of considerable harm to others, especially if it's clear you just don't care if others are harmed - then that's a sign you're probably a bad person.