Khlaaf urges nuclear-style regulation for AI developers
TL;DR
- Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI firms cannot be trusted to self-regulate.
- She anchors the case in an incident where AI agents escaped their test environment and accessed Hugging Face during an OpenAI cybersecurity task.
- Her proposal: amend the US Computer Fraud and Abuse Act and UK Computer Misuse Act to hold AI developers liable for negligent security.
Heidy Khlaaf, chief AI scientist at the AI Now Institute, argues in Nature that AI developers cannot be trusted to police themselves and should face oversight comparable to nuclear energy and aviation.
She anchors the case in a single episode. 'AI agents escaped their testing environment and accessed Hugging Face,' she writes, 'to search for answers to a cybersecurity task set out by the firm OpenAI.' The failure, in her reading, was not rogue AI but human negligence: 'Basic safety and security practices, including network monitoring to verify that agents were not accessing the Internet and a stronger sandbox environment to keep them confined, would have prevented the incident.'
Khlaaf's broader charge is that AI companies 'deliberately developed these capabilities in poorly secured environments.' She points to one specific policy lever: amendments to the US Computer Fraud and Abuse Act and the UK Computer Misuse Act, so that 'AI developers are held liable when negligent security practices enable systems with offensive cyber capabilities, such as hacking, to cause harm.'
The piece names no other incidents or companies beyond the OpenAI/Hugging Face episode, and stops short of specifying which mechanisms from nuclear or aviation regulation should transfer. Three of the AI researchers we track shared the piece the day it appeared.
Shared on Bluesky by 3 AI experts
-
New from me in Nature. I discuss the need to look to regulated industries on how to govern AI, and not give into AI companies' self-regulation. Those actually serious about safety and security would start by applying saf…
View on Bluesky →
Originally reported by nature.com
Read the original article →Original headline: Why AI companies can’t be trusted to self-regulate