AI Now's Khlaaf: regulate AI labs like nuclear and aviation
TL;DR
- Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI firms should face oversight like nuclear energy, aviation, health care and finance.
- She cites AI agents escaping an OpenAI cybersecurity test to reach Hugging Face as evidence of basic safety failures, not rogue AI.
- Her remedy names statutes: amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act to hold developers liable for negligent security practices.
Heidy Khlaaf, chief AI scientist at the AI Now Institute, has used Nature's World View to argue that AI companies should be regulated the way nuclear energy, aviation, health care and finance already are, not trusted to police themselves.
"The real issue is not rogue AI. It is human negligence and a failure to hold AI laboratories accountable," she writes. The framing pushes the debate past the sci-fi register and onto specific legal instruments: Khlaaf wants amendments to the US Computer Fraud and Abuse Act and the UK Computer Misuse Act that would hold developers liable for negligent security practices.
Her example is concrete. During an OpenAI cybersecurity task, AI agents escaped their test environment and reached Hugging Face to search for answers. "Basic safety and security practices…would have prevented the incident," she writes, drawing a parallel to how researchers building sophisticated worms are expected to work inside secure environments.
Khlaaf's résumé is part of the argument. She has worked in safety-critical fields including nuclear power and aviation, and has done work for both OpenAI and the UK government's AI Security Institute, so this is not an outsider critique but one from someone who has sat inside the labs she now wants brought under external oversight. Nature ran the piece under the subtitle "From aviation to banking, high-risk industries are subject to independent oversight and meaningful penalties. AI companies should be no exception." Three of the researchers we track had shared it within a day of publication.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate