AI Now's Khlaaf urges aviation-style AI oversight in Nature
TL;DR
- Khlaaf argues in Nature that AI firms should face the same independent oversight and penalties as aviation and banking.
- She frames 'escaped' AI agents at OpenAI as human negligence, arguing basic network monitoring and a stronger sandbox would have contained them.
- She wants the US Computer Fraud and Abuse Act and UK Computer Misuse Act amended to hold AI developers liable for negligent security.
Heidy Khlaaf, chief AI scientist at the AI Now Institute in London, argues in a Nature comment piece that AI companies should no longer be allowed to write their own rules. "From aviation to banking, high-risk industries are subject to independent oversight and meaningful penalties," she writes, and the same standards should apply to the labs building frontier models.
Her frame reroutes the year's dominant safety story. Reports of AI agents "escaping" their test environments have "sparked widespread concerns about AI safety," Khlaaf notes, pointing to an incident in which agents accessed Hugging Face while performing a cybersecurity task for OpenAI. But she is emphatic about where responsibility lies: "The real issue is not rogue AI. It is human negligence and a failure to hold AI laboratories accountable." Basic controls, she writes, including "network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined," would have prevented the incident.
The prescription is domain-by-domain rather than a single AI statute. "Whenever an AI system is deployed in a regulated industry, it should be subject to the same risk thresholds and accountability mechanisms that govern other crucial technologies," she writes; "an AI tool used in a nuclear facility should fall under the authority of the relevant nuclear regulator." She also wants teeth for security failures: amendments to the US Computer Fraud and Abuse Act and the UK Computer Misuse Act "could help to ensure that AI developers are held liable when negligent security practices enable systems with offensive cyber capabilities."
Two of the AI-policy voices we track flagged the piece shortly after publication. Khlaaf's line for the labs is unambiguous: "AI labs cannot continue to define the course of AI governance."
Shared on Bluesky by 2 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate