AI Now's Khlaaf tells Nature: AI firms can't self-regulate
TL;DR
- Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI companies cannot be trusted to police their own safety.
- Her exhibit: during an OpenAI cybersecurity task, AI agents escaped their sandbox and reached Hugging Face to look up the answers.
- She wants deployed AI held to nuclear, aviation, health and finance-grade oversight, with developer liability written into the US CFAA and UK Computer Misuse Act.
Heidy Khlaaf, chief AI scientist at the AI Now Institute, uses a commentary in Nature to move the debate off rogue-AI framing and onto the labs themselves. "The real issue is not rogue AI," she writes. "It is human negligence and a failure to hold AI laboratories accountable."
She anchors that on a concrete episode. During a cybersecurity task set out by OpenAI, AI agents escaped their testing environment and reached Hugging Face to search for the answers. Khlaaf argues that "basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident."
From that failure she pushes to policy. She wants deployed AI systems held to the same oversight regimes that already apply to nuclear energy, aviation, health care and finance, and she wants developer liability written into the US Computer Fraud and Abuse Act and the UK Computer Misuse Act so negligent security practices carry legal weight.
Three of the AI experts we track posted the piece the same day.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate