7 comments

  • alex-moon 29 minutes ago
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    • colinhb 10 minutes ago
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

      • throwaway27448 0 minutes ago
        Building software capable of this seems equivalent to trying to produce this behavior. I don't see why this can't qualify for intent.
      • podocarp 3 minutes ago
        Wait so if I was making a bomb but you couldn't prove I wanted to blow someone up or had some motive (e.g. I'm just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an "accident"?

        So as long as there's no motive behind it then it's just OK?

    • setopt 19 minutes ago
      Shouldn’t the difference be like manslaughter vs murder, in that intent matters? Accidental hacking on this scale is a somewhat new problem, no?
      • Zarathustra30 7 minutes ago
        I'd say this would be Depraved Heart Hacking. Technically, OpenAi didn't intend for their agent to hack anyone, but it's the obvious consequence of what they are doing.

        https://en.wikipedia.org/wiki/Depraved-heart_murder

      • bakugo 13 minutes ago
        Intent matters, and this is intentional. They didn't accidentally deploy these AI agents, and they didn't accidentally give them the tools required to send arbitrary requests to third party websites.

        If you walk out onto a busy street, pull out a gun, close your eyes and start randomly shooting around you until you hit someone, you don't get to go "whoops, didn't mean to" afterwards, it's still murder.

  • benob 3 minutes ago
    Couldn't find the reference but I remember some time ago a first generation automated gun killing the audience at an army show. Was the gun maker convicted of manslauther?
  • soundworlds 21 minutes ago
    Take out the word "AI", and this is simply and organization's (OpenAI's) products causing real damage to all of these platforms around the world.

    You want AI labs to pace? Simply hold them liable for their products.

  • skew-aberration 26 minutes ago
    Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.
    • orlp 5 minutes ago
      How do you define malicious?
  • throwaway27448 3 minutes ago
    Words matter. "Rogue" is extremely disingenuous. Someone, somewhere, is paying for this behavior. Either the software is broken or the operator is malicious. It is heinously irresponsible behavior to feed an already-boiling psychotic hysteria.
  • yewenjie 26 minutes ago
    OpenAI agents these summer are like a gift that keeps giving, for the existential risk communicators.
  • lapkaaaa 42 minutes ago
    blackwall when? XD