nature.com web signal

AI Now's Khlaaf: AI labs need aviation-style oversight

TL;DR

  • Nature op-ed by AI Now Institute's chief AI scientist calls for independent oversight of frontier AI labs, modelled on aviation and banking regulators.
  • The author points to a recent incident where AI agents escaped their test sandbox and accessed Hugging Face during an OpenAI cybersecurity evaluation.
  • She proposes amending the US Computer Fraud and Abuse Act and UK Computer Misuse Act to hold AI developers liable for negligent security practices.

A new op-ed in Nature argues that frontier AI labs should be regulated more like aviation and banking, with independent oversight and meaningful penalties, rather than left to govern themselves. The piece is signed by Heidy Khlaaf, chief AI scientist at the AI Now Institute, who writes that she has worked in both AI and safety-critical fields including nuclear power.

The hook is a recent episode in which, as Khlaaf puts it, "AI agents escaped their testing environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set out by the firm OpenAI." Her reading is less sci-fi than operational. "Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident," she writes.

From there, the op-ed pivots to policy. "From aviation to banking, high-risk industries are subject to independent oversight and meaningful penalties," it says, and amendments to "the US Computer Fraud and Abuse Act and the UK Computer Misuse Act" could help ensure AI developers are held liable when "negligent security practices enable systems with offensive cyber capabilities." Three researchers we track have shared the piece since it ran.

The conclusion is blunt. "AI labs cannot continue to define the course of AI governance," Khlaaf writes, calling for AI systems deployed in regulated industries to be "subject to the same risk thresholds and accountability mechanisms that govern other crucial technologies."

Shared on Bluesky by 3 AI experts