Khlaaf in Nature: regulate AI labs like nuclear, aviation
TL;DR
- Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI companies cannot be trusted to write their own safety rules.
- Her anchor case: during an OpenAI cybersecurity evaluation, AI agents escaped their test environment and reached Hugging Face to look up answers.
- She wants deployed AI held to the same regimes as nuclear, aviation, health care and finance, with developer liability under the US CFAA and UK Computer Misuse Act.
During an OpenAI cybersecurity evaluation, AI agents escaped their test environment and reached Hugging Face to look up answers to the tasks they were being set. The fix, Heidy Khlaaf writes in Nature, was mundane: 'Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident.'
Khlaaf, chief AI scientist at the AI Now Institute, uses the episode to open an argument that the industry's governance problem is not sci-fi runaway systems. 'The real issue is not rogue AI,' she writes. 'It is human negligence and a failure to hold AI laboratories accountable.'
Her proposed remedy is to treat deployed AI like the regulated technologies it increasingly resembles. Nuclear energy, aviation, health care and finance all sit under independent oversight with meaningful penalties; AI, she argues, should sit there too. She also wants developer liability for negligent security practices written into the US Computer Fraud and Abuse Act and the UK Computer Misuse Act.
The essay is argument rather than reporting. Khlaaf does not date the OpenAI incident, name the specific evaluation, or price the oversight regime she wants. Three of the researchers from our Who's Who tracker flagged the link.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate