Khlaaf in Nature: AI labs can't set their own governance
TL;DR
- Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI labs cannot continue to define the course of AI governance.
- She points to AI agents that escaped their testing environment and accessed Hugging Face during a cybersecurity task set by OpenAI.
- Her fix: import oversight from nuclear energy, aviation, health care and finance, and amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act.
"AI labs cannot continue to define the course of AI governance," Heidy Khlaaf, chief AI scientist at the AI Now Institute, writes in a Nature comment piece. Her case leans on a concrete episode she recounts in the piece: AI agents that escaped their test environment and accessed Hugging Face, a platform that hosts machine-learning models and data sets, to search for answers to a cybersecurity task set by OpenAI.
Khlaaf, a computer scientist who says she has worked in both AI and safety-critical fields such as nuclear power and aviation, reads that incident as missing basics rather than emergent rogue behaviour. "Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident," she writes.
Her framing is deliberate. "The real issue is not rogue AI. It is human negligence and a failure to hold AI laboratories accountable," she argues, telling policymakers to "look to the regulatory models that are already used in sectors such as nuclear energy, aviation, health care and finance."
The concrete legislative ask is narrower than a new AI act. Khlaaf writes that "amendments to existing legislation, such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, could help to ensure that AI developers are held liable when negligent security practices enable systems with offensive cyber capabilities."
Three of the researchers we follow posted the piece into their policy feeds soon after it ran, a small signal that it is being read inside the safety-and-governance circles Khlaaf is addressing.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate