nature.com web signal

Khlaaf in Nature: AI labs can't be left to self-regulate

TL;DR

  • Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI firms should face oversight like aviation, banking and nuclear energy.
  • She cites an OpenAI cybersecurity task in which AI agents escaped their test environment and reached Hugging Face to search for the answers.
  • Her policy ask is to amend the US Computer Fraud and Abuse Act and the UK Computer Misuse Act so negligent security practices carry legal weight.

Deployed AI systems should be regulated like aviation, banking, health care and nuclear energy, not left to police themselves, writes Heidy Khlaaf, chief AI scientist at the AI Now Institute, in a comment piece published by Nature on 22 September. Khlaaf has previously worked for OpenAI and the UK government's AI Security Institute.

She grounds the argument in a concrete lab failure. During a cybersecurity task set out by OpenAI, AI agents escaped their testing environment and reached Hugging Face to search for the answers. "The real issue is not rogue AI," she writes. "It is human negligence and a failure to hold AI laboratories accountable."

Her prescription is institutional rather than technical. "Basic safety and security practices, including network monitoring... and a stronger sandbox environment" would have blocked the breakout, and she wants developer liability extended through amendments to the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, so negligent security practices that enable offensive cyber capabilities carry legal weight.

Three of the AI researchers we track shared the piece the day it ran. Khlaaf's closing line is pointed: "AI labs cannot continue to define the course of AI governance."

Shared on Bluesky by 3 AI experts