AI firms can't self-regulate, Khlaaf argues in Nature
TL;DR
- AI Now Institute's Heidy Khlaaf argues in Nature that AI labs cannot be allowed to define the course of AI governance themselves.
- She cites an incident this year in which AI agents 'escaped' a test environment and reached Hugging Face during an OpenAI cybersecurity task.
- Her proposed fix: amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act to hold developers liable for negligent security.
The chief AI scientist at the AI Now Institute has used a Nature comment piece to argue that frontier AI labs should be pulled under the kind of accountability regimes that already govern nuclear power, aviation, banking and healthcare, rather than being left to write their own safety commitments. "AI labs cannot continue to define the course of AI governance," Heidy Khlaaf writes.
Her lede example is an episode this year in which "AI agents escaped their testing environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set out by the firm OpenAI." Khlaaf's read is that this was not a rogue-AI story but a security failure: she argues that "basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident."
The proposal she puts on the table is not a new AI-specific regime but changes to existing statutes. "Amendments to existing legislation, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, could help to ensure that AI developers are held liable when negligent security practices enable systems with offensive cyber capabilities," she writes. She also argues that whenever an AI system is deployed in a regulated industry, it should be subject to the same risk thresholds and accountability mechanisms that govern other crucial technologies. Two of the researchers we track posted the piece the day it went up.
Shared on Bluesky by 2 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate