AI Now's Khlaaf calls for aviation-style oversight of AI labs
TL;DR
- Khlaaf, AI Now's chief AI scientist, argues in Nature that AI firms need oversight modelled on nuclear, aviation, health care and finance.
- She cites an incident where AI agents escaped their test environment and accessed Hugging Face to search for answers to an OpenAI cybersecurity task.
- She proposes amending the US Computer Fraud and Abuse Act and UK Computer Misuse Act to make developers liable for negligent security practices.
Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in a Nature commentary that AI developers can no longer be left to police themselves and should be governed by the same frameworks that cover nuclear energy, aviation, health care and finance. Three of the researchers in our tracker shared the piece after it ran.
Her lede example is a sandbox breach. 'AI agents escaped their testing environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set out by the firm OpenAI,' she writes. The remedy, she adds, was neither novel nor expensive: 'Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident.'
Khlaaf, who writes that she has worked in both AI and safety-critical fields including nuclear power and aviation, wants that liability written into existing cyber law. 'Amendments to existing legislation, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, could help to ensure that AI developers are held liable when negligent security practices enable systems with offensive cyber capabilities, such as hacking, to cause harm,' she writes. The reference industries are already running the pattern: 'From aviation to banking, high-risk industries are subject to independent oversight and meaningful penalties.'
Her closing is the thesis: 'The broader lesson is that AI labs cannot continue to define the course of AI governance.'
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate