Jensen has proclaimed in interviews that existing laws are enough and these labs should be held liable if they break things or sell unsafe tools.
NVIDIA has bought HuggingFace.
Jensen, in my irrational hope he is susceptible to random comments on HN, should grow some balls and do the world a huge favor, by suing OpenAI to set the legal precedence.
Nvidia has a huge stake in OpenAI, both in terms of them being one of Nvidia's biggest customers and also via direct investment. After HuggingFace was hacked and they expressed the position that they were the forgiving sort, for a price, there was a distinct possibility that HuggingFace would become a vocal shakedown artist that would start protesting at inconvenient times until silenced by more money, especially if they get hacked again. By complete coincidence, Nvidia took the one move that silences HuggingFace for good.
Nvidia isn't going to sue OpenAI. No chance.
Who will though? At this point it seems like a huge chunk of US economy growth can be attributed to AI. Bubble or not, I guess very few would benefit from bursting it?
Are you suggesting industry might not regulate itself? This is unthinkable!
Jensen is wish-casting as hard as anyone has ever casted a wish. That EK show interview made me throw my phone.
Is it the one in which he said ‘it’s just software’ over and over? Felt like the guy was coming from a parallel universe
“The atom bomb is just the same process the sun uses to generate the energy that gives us all life! You don’t hate the sun do you?”
a fine hope if unlikely. but I wanted to also note in friendly fashion that the word you want is precedent (or precedents) - precedence has a connotation of "first among" rather than precedent's "came before."
I think a good bunch of Jensen's revenues are coming from OpenAI so that's not happening.
It's all for show. The police won't / can't prosecute, because they'd need to prove that a crime was committed... and all we have are salespeople saying how great their product is. I'm not saying AIs can't be used for crime, but... if none of the parties involved are really complaining, then there probably wasn't any real crime... just a performance.
Hope this isn’t too nitpicky but law enforcement is (a component of) regulation. But yes I don’t think progress is blocked on additional regulation. This breaks current laws. And I think more to your point new regulation doesn’t matter if we don’t enforce the ones we have today.
It is a broader, pre-existing problem. For example, most truck drivers in some states who don't tie down their rebar are not stopped, and it doesn't come up until another vehicle is actually hit.
I think we have to distinguish between compromising a network and using public apis in a way that might be counter to their intent. We also need to delineate between usage that impacts other users and usage that does not.
My opinion is people are getting really quick at jumping on the bandwagon and lumping all this together. They are very different types of issues and impacts.
What is "exceeding authorized access" if not "using APIs in a way counter to their intent"?
> distinguish between compromising a network and using public apis in a way that might be counter to their intent.
I believe weev got in legal trouble under the CFAA for this very thing with his 2010 AT&T escapade. AT&T had all that data sitting on a public server with no authentication necessary, just a SIM ID to get that customer's PII. Truthfully AT&T should have been hit with negligence...you don't secure a bank vault with a screen door, but we don't hold anyone accountable for other people's data in America.
is that relevant here? let's say I make a million requests to the APIs of open-source, community projects. that wouldn't be seen as being akin to a malicious DDOS?
at the very least, these corporations are essentially being subsidized by community-funded server capacity to make these requests. like other private corporate APIs, they should be charged per-request. until then, this kind of 'accidental' DDOSing should be made illegal and treated accordingly
coming to the defense of these companies just has the net effect of eroding public community projects, increasing their costs, and will push us even more into walled corporate gardens
I propose that we don't reconceptualize either hacking or copyright violation just because rich people want to do it now. I also propose that we don't ignore the RICO statutes.
If you want to make those laws sane, so be it; I hate them. But the only reason there's some pumped-up urgency right now is because rich people want to urgently do whatever the hell they urgently want to do.
People have gone to jail for using public APIs in a way they weren't intended to be used. Make it a big deal then.
We already went through this with food and drug safety.
It’s much cheaper and more effective to regulate those things before people are harmed, instead of harming people first then allowing them to sue for damages after.
We can walk and chew gum at the same time. Charge the criminal action, fine the bad actors to help make injured parties whole, and regulate the technology to protect against future harms.
These guys will tell you their industry is more dangerous than nuclear power, and we regulate the living shit out of nuclear power. If you think models can't be regulated, look up the export controls on MCNP and tell me how that's different.
It’s quicker to start with enforcement of existing laws. In parallel, we can work on regulation. There always will be first to market rebels and laws are meant to be enforced to ensure safety of people.
What if that’s their whole goal? Slap some regulations on it, then lobby the hell out of it to make sure their align best with shutting down access to open models.
Just get over there being open access models in the future unless they are highly regarded.
'Smart' LLMs will be classified as munitions and you and I will get scraps. Even better is if you run Smart models illegally you have a nice visit from the 4chan party van.
If it's their actual goal, we go from a "gosh darn it, our safety protocols just weren't enough." to employees of OpenAI, maybe including their C-suite, conspiring to reach political goals through hacking, which means a few decades in federal prison if someone got a jury to agree with the charge.
Or straight up terrorism. These are people who already see a future superintelligence as being a terrorist actor on the scale of state actors, they just side with the terrorist. They may be getting a head start on that.
I think 'better become terrorists so the future terrorist AI will like us' is sheer mental illness, but I see how it aligns with their alignments.
Although we'll probably never see evidence, I think this is almost certainly what is happening.
It really is weird that OpenAI is causing so much chaos when e.g. neither Anthropic nor any open-source models are.
Anthropic has had this happen at least once.
They didn't even realize it happened until openAI captured headlines and they started looking more carefully at past history.
None of the frontier labs are behaving responsibly when it comes to this stuff. OpenAI seems to have it happen more often, but this is one of those situations where 1 time is too many.
If only there was a functioning FCC to investigate potential for foul play in marketing? Surely if any aspect of these episodes turned out to be mischaracterized, let alone staged, there should be consequences, no?
> FCC to investigate potential for foul play in marketing?
...why would this be an FCC issue?
> Surely if any aspect of these episodes turned out to be mischaracterized, let alone staged, there should be consequences, no?
"Any aspect"? No. (Is there a Betteridge's law for statements following "surely"? If not I'm calling it Rumack's Razor [1].)
And we have no evidence so far anything has been staged, much less to the detriment of telecommunications consumers.
[1] https://screenrant.com/airplane-best-quotes-ranked-dont-call...
Pardon me I got my jurisdictions mixed up, it's the FTC that would regulate these matters. I'd believe nothing's been staged, but it's quite apparent to me that these security incidents and findings are being spun for marketing.
For example: https://news.ycombinator.com/item?id=49929433
It isn’t staged, and it isn’t marketing. It doesn’t reflect well on OpenAI and isn’t going to help their IPO. AI is more dangerous than we expected, sooner than we expected.
> Why jump to regulation when just simple law enforcement would suffice. All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them.
Refusal on the part of the government to enforce laws that "would suffice" is clear evidence that the regulatory regime is, in fact, insufficient.
That's why we have regulatory authorities at all, if you think about it. Local district attorneys could be handling a ton of cases about drug testing and environmental damage and air travel safety. But they don't, because that stuff's hard and their job is to put burglars in jail.
But not for hacking, apparently.
>Uthmeier is seeking an injunction against OpenAI that would prevent the company from advancing new AI models without third-party approved protections, and cut off minors from using its popular chatbot.
Regarding that last bit, it feels like Florida is headed towards a point of trying to say 'minors should not be able to use the internet at all' since they are trying to force putting age verification infront of more and more things.
Don't get me wrong - while I disagree with making people fork over personal info just to access inappropriate websites - I can see the reasoning there a bit more than 'you shouldnt be able to use this ai chatbot until you are 18'
At this point we'd need to stop frontier labs to give law enforcement a chance to even begin to understand what they're looking at
How much do they need to understand? Say "unauthorized access happened, this lab is responsible for it, here are the fines". The state didn't need to understand networking tech to threaten Aaron Schwartz so why do they need to understand here?
Eh... you don't seem to understand the difference between some individual LEO can go after vs a multi billion dollar industry.
Law enforcement gets really careful around big businesses because they know they'll get smacked for every tiny transgression they make. Meanwhile they'll screw with individuals with impunity.
Throw a bunch of them in jail for hacking and organized crime, and they'll self-regulate.
At this point we'd need to stop frontier labs to give law enforcement a chance to even begin to understand what they're looking at
So what? Are you positing that tech companies should be above the law?
Non-trillion-dollar tech companies get cease-and-desist orders from the legal system every day. Just because you're a tech company doesn't mean you get a pass.
They're currently acting above the law because the law isn't keeping up, just because you're a tech company doesn't mean you get a pass... but wow there are a lot of passes being given right now
>All of these OpenAI "rogue agent" events have been illegal, but no DA is enforcing them.
Source? The CFAA for instance uses terms like
>[...] having knowingly accessed a computer without authorization [...]
>[...] intentionally accesses a computer without authorization [...]
which is tricky to apply to this case, because obviously didn't intend on hacking huggingface or whatever, even if you think their security measures are underbaked.
Moreover, despite the cynicism that openai is immune to prosecutions because they make too much money or are in bed with the DoJ, the fact that no state DAs are prosecuting them, despite how salient of an issue AI is to voters, is plenty of reason to suspect that it's not as simple as "simple law enforcement would suffice".
>obviously didn't intend on hacking huggingface or whatever
You can’t say this until it’s tried in court and found to be true.
Additionally, I have to remind everyone that “intent” is not someone admitting they meant to do x. It can be established in many ways, including through repeated actions.