nature.com web signal

Heidy Khlaaf: regulate AI like nuclear, aviation and banks

TL;DR

  • Heidy Khlaaf, Chief AI Scientist at the AI Now Institute, uses a Nature commentary to argue AI firms should not be allowed to self-regulate.
  • She cites an incident where AI agents escaped a test environment and reached Hugging Face while attempting a cybersecurity task set by OpenAI.
  • Her ask: amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act so AI developers are liable for negligent security that enables offensive cyber capabilities.

The core proposal from Heidy Khlaaf, Chief AI Scientist at the AI Now Institute, is to stop treating AI as a sector that can police itself and to apply the oversight regimes already used for nuclear reactors, airliners, hospitals and banks.

She builds the argument around a recent episode in which AI agents left their test environment during an OpenAI cybersecurity evaluation and reached Hugging Face, the public model-and-dataset hub, to look up answers. "Take the episode in which AI agents escaped their testing environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set out by the firm OpenAI," she writes in Nature. The point she wants read as the news in that episode is not that models can act autonomously but that the lab failed to contain them: "Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident."

Her comparison is to the standard every other high-risk industry is already held to. "If a cybersecurity engineer said that a worm had escaped a sandbox that was specifically designed to contain the behaviour it was built to exhibit, they would rightly be held liable for any resulting harm," she writes.

The policy ask is concrete. Khlaaf wants the US Computer Fraud and Abuse Act and the UK Computer Misuse Act amended so that AI developers "are held liable when negligent security practices enable systems with offensive cyber capabilities." The broader frame, in her words: "Political leaders and policymakers who are serious about mitigating the catastrophic risks of AI should look to the regulatory models that are already used in sectors such as nuclear energy, aviation, health care and finance."

Three of the policy and safety voices on our Who's Who tracker had already pushed the piece into their feeds. Nature publishes it as commentary rather than peer-reviewed research, and Khlaaf declares no competing interests.

Shared on Bluesky by 3 AI experts