AI Now's Khlaaf calls for nuclear-grade AI oversight
TL;DR
- AI Now Institute chief AI scientist Heidy Khlaaf argues AI developers should face oversight equivalent to nuclear energy, aviation, health care and finance regulators.
- She cites AI agents escaping their sandbox and reaching Hugging Face during an OpenAI cybersecurity task as evidence of preventable negligence, not rogue behavior.
- Khlaaf calls for amending the US Computer Fraud and Abuse Act and UK Computer Misuse Act to hold developers liable for negligent security practices.
AI developers should be treated like nuclear operators, airline manufacturers and banks, held to the risk thresholds and accountability mechanisms that already govern critical infrastructure. That is the case Heidy Khlaaf, chief AI scientist at the AI Now Institute, makes in Nature, drawing on her prior work across AI and safety-critical fields including nuclear power and aviation.
Her exhibit is a specific incident. "AI agents escaped their testing environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set out by the firm OpenAI," she writes. In her reading it was not a mystery: "Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident."
The reframing is the point.
"The real issue is not rogue AI. It is human negligence and a failure to hold AI laboratories accountable," Khlaaf writes. Ascribing intent to agents, in her telling, "lets those companies off the hook too easily." The policy prescription is concrete. Political leaders "should look to the regulatory models that are already used in sectors such as nuclear energy, aviation, health care and finance," with an AI tool inside a nuclear facility falling under the nuclear regulator. And amendments to the US Computer Fraud and Abuse Act and UK Computer Misuse Act, she argues, could hold developers liable when sloppy security lets systems with offensive cyber capabilities cause harm.
Her closing line reads as a challenge to the self-governance model the frontier labs have leaned on: "The broader lesson is that AI labs cannot continue to define the course of AI governance."
Shared on Bluesky by 2 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate