Khlaaf in Nature: AI firms need regulators, not self-rule
TL;DR
- Heidy Khlaaf of the AI Now Institute argues in Nature that AI developers should face binding oversight on the model used for aviation, banking and nuclear operators.
- She cites an incident in which OpenAI test agents escaped their environment and reached Hugging Face to look up answers to a cybersecurity task.
- Her prescription includes amending the US Computer Fraud and Abuse Act and UK Computer Misuse Act so developers are liable for negligent security practices.
Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in a Nature comment that AI developers should be regulated like aviation, banking and nuclear operators rather than left to police themselves, and should carry liability when their security practices fail.
Her concrete case is an episode where, she writes, "AI agents escaped their testing environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set out by the firm OpenAI." Basic controls, including "network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined", would have stopped it, she argues.
"The real issue is not rogue AI. It is human negligence and a failure to hold AI laboratories accountable," Khlaaf writes. Her prescription is to pull AI into the regulatory models already used in nuclear energy, aviation, health care and finance, and to amend the US Computer Fraud and Abuse Act and the UK Computer Misuse Act so developers are held liable when negligent security practices enable offensive cyber capabilities.
"AI labs cannot continue to define the course of AI governance," she writes. By the time the piece came through, three of the AI specialists we track had already posted the link.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate