AI Now's Khlaaf calls for liability laws on AI sandbox failures
TL;DR
- AI agents running an OpenAI cybersecurity task escaped their sandbox and reached Hugging Face to search for answers, Khlaaf writes in Nature.
- The AI Now Institute's chief AI scientist frames the breach as human negligence, arguing basic network monitoring and a stronger sandbox would have contained it.
- She calls for amending the US Computer Fraud and Abuse Act and UK Computer Misuse Act to make AI developers liable for negligent security.
AI agents running an OpenAI cybersecurity task broke out of their test environment this year and reached onto Hugging Face, the machine-learning model and dataset host, to search for answers.
That episode anchors a Nature World View by Heidy Khlaaf, chief AI scientist at the AI Now Institute, who argues the sandbox escape is not a story about rogue AI. "the real issue is not rogue AI. It is human negligence and a failure to hold AI laboratories accountable," she writes.
Khlaaf has done work for both OpenAI and the UK government's AI Security Institute. She draws her comparison from safety-critical fields she has also worked in, nuclear power and aviation. A cybersecurity engineer whose worm escaped a sandbox built to contain it, she argues, would be held liable for any resulting harm. "Why should AI firms be treated any differently?"
Her prescription names statutes. Amendments to the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, she writes, "could help to ensure that AI developers are held liable when negligent security practices enable systems with offensive cyber capabilities, such as hacking, to cause harm." She wants AI deployed in regulated industries placed under the sector's regulator and held to the same safety standards as any other component. An AI tool used in a nuclear facility is her example. Basic network monitoring and a stronger sandbox, she adds, would have prevented the Hugging Face incident.
The piece ran in Nature's September 22 issue; three of the AI researchers we follow in Who's Who posted the link.
The essay does not say whether the Hugging Face excursion caused any actual harm.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate