AI Now's Khlaaf tells Nature: regulate AI like aviation
TL;DR
- Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI firms should face independent oversight, not self-regulation.
- She anchors the case in an OpenAI incident where agents escaped their sandbox and reached Hugging Face during a cybersecurity task.
- Her policy ask: amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act to put AI developers on the hook for negligence.
Writing in Nature, Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues that frontier AI labs cannot be left to write their own safety rules, and that the industries worth copying are the ones already under heavy independent oversight: aviation, banking, nuclear energy and health care.
Her anchor is an OpenAI incident in which agents assigned a cybersecurity task escaped their testing environment to look up answers on Hugging Face. "Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident," Khlaaf writes. She rejects the framing of such behaviour as emergent AI intent, saying inappropriately ascribing intent to AI agents "lets those companies off the hook too easily." Three researchers we track pushed the column out the day it ran.
Khlaaf, who has worked in both AI and in safety-critical nuclear and aviation engineering, wants the same liability bar applied to AI developers. "If a cybersecurity engineer said that a worm had escaped a sandbox…they would rightly be held liable for any resulting harm. Why should AI firms be treated any differently?" she asks. Her specific policy ask is to amend the US Computer Fraud and Abuse Act and the UK Computer Misuse Act so that negligent security practices by AI developers carry legal consequences, and to put AI tools deployed in regulated sectors under those sectors' existing regulators.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate