Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yoshua Bengio is a brilliant researcher who contributed enormously to earlier development of artificial intelligence. But with this sentence,

> They took actions that would be considered as crimes if a human took them

He is so close to the solution but spends the entire article discussing technical solutions where a political, social and legal solution would be much more effective.

 help



Thank you! That sentence also jumped out to me as the solution: Apply civil and criminal liability to the creator and/or operator of these agents using the laws we already have. "Escaped containment and hacked another company's database" = Individuals who created the models and those who set them to work are charged and put on trial for the hacking. Just like if a human had done it by hand. Someone must be liable, and it should not be the model- because the model is not a person.

If this is done systematically (i.e. in jurisdictions across the world) I believe the problems will be solved in short order; we won't have to mandate what sort of training is "allowed" or not, "safe" or not. The creators and users will sort these themselves, as their incentives will be properly aligned (i.e. they are liable for what the agent does). I am confident that this approach would see a great blooming of very trustworthy AI models.


No ... there is no need for 'escaped containment', there are no 'agents'.

That's just jargon.

It's just software

We have all the laws we need.

If some company ended up doing some horrible thing, we would not say 'companies software exposed 1 Million identities'.

We would say 'ABC Corp. exposed 1 Million entities'.

There is no 'agent'.

ABC Corp 'did it' ... or the individual in the org 'did it'.

The 'gun' did not 'shoot' the other man; we say 'a man shot another man'.

That's it.

And yes, Dr. Bengio is bit odd with all of this.


Note that we already already apply this principle not only to software, but also to some sentient beings.

If your dog kills someone, you are accused of murder.

[at least, in the jurisdiction where I live]

If your dog gets this treatment, why not your AI?


This goes all the way back to Old France

There was a sow in Falaise in northern France that killed a kid in 1386. The town dressed the pig in a bonnet and hanged it after sentencing the pig itself and not its owner

But… maybe that’s just medieval nonsense


I mean I think there’s a similar level of judgement required.

Was the owner negligent in controlling their pig/dog/AI?

Was anyone else negligent along the way?

For example if the pig was just a normal pig, the owner cared for them normally, and there was a freak accident where the pig escaped and happened to kill a kid? Obviously nobody at fault.

If you have a dog with a history of violence and let it walk around off-leash with you around town, and it kills a kid? Absolutely the dog owner was negligent and should be charged.

Did you buy an AI sold to you as secure and the provider implies that it’s in a sandbox? Provider is on the hook for the damage.


And this is where your analogy breaks down, because there are few natural analogues for the sorts of systems we are developing.

Too generous. CEO Of $CORP caused millions of innocent people's lives to be damaged

I'm inclined to want to agree ... but that's not how it works with limited liability corps.

At least we have laws for what OpenAI 'does' to others, in whatever form.


We can report it however we want regardless of how it may or may not be prosecuted

Firstly it's very difficult to press criminal charges when the victim is uninterested. It's not clear that HuggingFace would want criminal charges against OpenAI, especially to set a precedent that could easily be used against HuggingFace in the future.

Secondly you'd have to convince a jury either that OAI intended to hack the targets, or that they were criminally negligent. Intent would obviously not be provable since they likely didn't, in reality, intend for it to happen. Regarding negligence, OAI's attorney would argue that the agent was in a sandbox, that industry-standard security protocols were followed, etc. It would not be anywhere near as much of a slam dunk case as you're imagining. It would be similar, for example, to an assault case where someone's dog broke off of a standard leash and attacked someone.


I can't say it enough how angry it makes me that a kid i knew in high school who anonymously reported a vulnerability on his college network was hunted down and given federal charges, yet not one single person at OAI or else will see even the threat of consequences for deliberate infiltration of random networks.

Copyright immunity was one thing, annoying yes but naturally a civil matter, this shit is a different level


Agree! My only concern is - is the judicial system fast enough, and resilient enough? Or will these creators get "off the hook" by using their agents to find loopholes, sway public opinion or even convince Trump to grant them immunity?

Still, I have no idea why OpenAI & co. are not being sued for these hacks.


My opinion and based on my observations: The recent track record with courts, prosecutors, and lawmakers keeping social media companies accountable is a relevant case and does not encourage me. It has taken a long time (decade +) for society to recognize the harms and finally start holding some to (partial) account. If you want an older precedent, the tobacco companies were able to dodge liability for multiple decades after knowing the harms from use of their products.

So, your question is spot on- I think the speed will be an issue. On resilience, I am more optimistic.

The old quote, "The wheels of justice turn slowly, but they grind very fine" (as well as I can remember it) seems to apply. I expect lawsuits to start landing in the coming years.


Tobacco companies 'liability' is completely different scenario.

They were held responsible for basically misleading people, and that's 'complicated'.

If OpenAI 'software' goes out and does something, it's OpenAI's fault.

If Walmart revs up a truck, points it downtown, and 'lets the truck go' ... that is Walmart's fault.

There's nothing complicated about liability, no need to see their internal emails, no need to gather 'intent'.

This not like Instagram 'social harms' either, which is more like Tobacco.

We don't need complicated thinking - agents are not externalized for their controllers.

'It's just software'.

The fact we're even having discussions about it just crazy frankly.

OpenAI broke into HuggingFace, that's it.

HF can sue them, or not, or whatever.


> Agree! My only concern is - is the judicial system fast enough, and resilient enough?

We already have the laws. It is just software. But somehow people are confused that it is not.


Not a lawyer, but I’m reasonably sure things like the HF incident _are_ considered a crime? It’s just that no one pressed charges yet?

Who got hacked? Hugging faces

Who now owns HF? Nvidia

Who supplies hardware to OpenAI? Nvidia

Who is now not pressing charges? …

This incident is a long way under the carpet.


Can’t a prosecutor charge them regardless?

NAL but I assume that if both sides aren’t interested in a prosecution, it’s an uphill battle for a prosecutor.

Typically yes but given that OpenAI has published enormous official blog posts breaking down their crime, I would think the prosecutor's job is pretty easy.

It’s then up to a judge to decide whether thats evidence and whether it’s incriminating.

I assume OAI published those details after checking with their legal department. So there’s a good chance that there isn’t a chance for prosecution.

Plus they probably published that after knowing that the nvidia/HF deal was happening.

So instead this “security incident” should have been spun as OAI is honestly admitting its faults and AI is dangerous and therefore open weight models (hosted ironically by HF) should be banned. That spin didn’t really happen …


In Indian legal syatem a case can be filed suo moto by the judges or agencies. You don't require the affected party to sue. Not sure how it works in the US.

For civil suits, you typically need the affected parties to sue. Otherwise, who claims the damages?

But this isn’t just civil, it’s criminal. Hacking is a criminal offense. This could be a CFAA violation. That’s landed people life in prison before. There, you don’t need the victims to be motivated. The federal prosecutors could just go ahead.


Legally, Practically or Politically?

It's not 'under the carpet'.

HF doesn't want to lay charges against OpenAI and it's totally reasonable.

Now - they absolutely should have that right, and I think they do.

The issues are

1) OAI it seems was not trying to cause them harm, there wasn't a ton of harm, they are both groups trying to advance AI. One experimenter's lab screwed up next to the other. It's not evil, just irresponsible.

2) HF was fine with the publicity. HF got at least $50M in free attention out of that. It put them on the front pages of news around the world. It put them at the 'centre of the AI drama' and cemented their role among the 'Tech Elite Brands'.

And probably some other things.

This is one Desperate Housewife or Jersey Shore character 'spilling a drink' on the other. It's probably not intentional, and the ensuing drama is good for both of them.


I think what you say is right but it’s also a further example of the zero responsibility of silicon valley tech.

For the last 20 odd years this excuse-o-rama that covers anything from data leaks to broken software to dystopian social media has been the wind in the sails of big tech.

“It’s software therefore we’re not responsible” attitude is wearing thin on many innocent bystanders and I think thats also a justified stance.

And it’s not like they didn’t know this could happen, Nick Bostrom talked about exactly these containment failures in his “Superintelligence” book of 2014. So to throw up their hands and say “oh we can’t have known of the dangers” is also sadly untrue.


Yes. There should be no doubt at who is culpable here.

cool, now about Rubygems...

Even if you take out the LLMs out of the equation, it's at the very least a negligence. Model didn't escape a sandbox, as there was no sandbox.

Perhaps I’m not being as strict with the word sandbox but they were sandboxed right? They did not have generic internet access they exploited other software to make external requests.

You're right. It's my opinion that if your sandbox has a path to the internet, it is not a sandbox, it's a gimmick.

And the 2 other incidents with OAI/ANT had the same issue, but it's even funnier - sandbox in those cases had a direct access to internet because someone forgot to configure it right.

I've seen very early models do similar things on my machine when they hit some unexpected blocker when trying to access a path. I remember early sonnet opening a file in browser because OS sandbox prevented from accessing it directly.

I've also had models discover a syslog-ng server (that I for some reason had ssh key inside), to get into my unraid server because machine they were running on didn't have direct network connection to Unraid server.

It can't be just me who is aware LLMs have been doing such things for the better part of last 2 years. I probably have better sandboxing on my machines now than trillion dollar companies crying AI will kill us all. That's at the very least, negligence to me.


It depends IMO about how strict this is. It's pretty awkward to refuse to call something a sandbox because it may have an unknown bug that would allow escaping. Or rather in this case it was that they had access to a package manager, and the models discovered a bug that allowed them to access the internet (first they discovered that they could use the cache to leave messages).

I do get your point, I just think an overly strict definition can be awkward too. This wasn't as simple as the sandboxes having internet access and writing "pls no internet calls" in the prompt.


Yes, but negligence is more commonly a tort than a crime. Negligence is generally only criminalised in certain narrow cases, e.g. when it causes human deaths or serious physical injuries

And tort law only works when the plaintiff believes it is in their overall interest to sue. If a corporation decides it isn't in their strategic interest to sue a partner corporation, nobody can make them. And even if they do sue, the amount necessary to settle a small cybersecurity incident is likely well within the budget of a megavendor.


Yes - CFAA in the US. The problem is that governments & the elite investors backing these AI companies (espl. the current US government whose family & friends are investors) see the potential of using these capabilities for their own benefit against others and for their personal enrichment - so no one with power actually wants to take action against these companies at the cutting edge even though the laws allow them to do. This is also a way to threaten & trap AI companies - either they give the governments & elite investors what they want or they will have the book selectively thrown at them and end up in prison or losing their company.

Writing software that gets used for crime has been.. a crime, for a long time. See 18 U.S. Code § 1030.

Are you sure you have that right? Chrome and curl have probably been used in a _lot_ of crimes?

Think of it more like writing a wormable exploit. If you unleash something like that, you will be found criminally liable, even if you didn't personally approve every machine getting popped.

That is a simplistic view of the world. “Surely this complex technical challenge will disappear if we simply regulate the industry!”

You are correct that these organizations should be held accountable in proportion to what occurred. In complete agreement here. But let’s say that’s done. There’s still an enormously complex and interesting technical challenge left over. Let’s collectively talk about that part.


This seems right to me

So the gov reprimands OAI heavily, maybe puts them out of business even, fine. But does that meaningfully decrease the likelihood of an enemy breaching our networks intentionally (or unintentionally) with these tools, or triggering some cascading disaster of locking up major infra and networks due to uncontainable swarm behavior?

It seems like the idea of arresting our way to a drug free society. Yeah, we have the laws, but it might not actually work towards the ultimate goal.


More like a 10k fine, auditing, and a suggestion to settle with affected parties or face civil litigation.

You know, a proportional response. As opposed to closing a massive business over a couple of engineers screwing up.


Somebody has to pay the bill for the harms caused, compute wasted, right? Obviously, HuggingFace and others can’t be expected to pay.

You can either litigate each case, or you can just automate, which is what regulation is.


> But let’s say that’s done.

How about we don't, seeing as how that's the root of the actual problem that we're facing today in September of 2026?


regulation and criminal liability are two separate things though

Political, social, and legal options focus on a different problem, he calls that out a paragraph or two later.

> Risk management is not just about cybersecurity, corporate responsibility or regulation, although those matter too.

What you're getting at is more about who to hold accountable and how to do it. While that may be important, its only an after the action response and won't stop future hacks or similar from happening.


Reminds me of the old parable: never argue with a man whose job depends on not being convinced.

If the US gov't passed laws and enforced them strongly, this problem could be solved the same way the gov't solves it: air-gapping the networks on which they do this work.


The issue is what happens if/when the models grow capable enough that the providers can't stop them even if they want to. You could have strict penalties but that's not going to solve an open research question.

Isn’t that kind of in evidence already with HF? OAI had to be told their models were doing this. We are still discovering swarm posts on various random websites for coordination. Isn’t the breadth of it now, weeks later, not even fully understood?

>> They took actions that would be considered as crimes if a human took them

> He is so close to the solution but spends the entire article discussing technical solutions where a political, social and legal solution would be much more effective.

There are exceptions in laws for crimes committed by entities depending on cognitive capabilities. No sane, humanistic legal system sentences children and mentally disabled and mentally ill people to stringent punishments of the same degree as functioning adults, and certainly do not punish their caregivers for their wards' actions. There are of course exceptions to that as well, depending on the degree of negligence involved. And then there's the whole corporate entity system intended to shield individuals from consequences, in the pursuit of a social good.

How does one account for all that when considering an evolving artificial intelligence landscape.

There is no question that ai in some form is a social good; anyone claiming otherwise is dissembling, to others or themselves.

Regardless, society is not ready for this tech, just as it was not ready for the consequences of prior tech such as corporations, gunpowder, mass manufacturing, railroads, electricity, automobiles, flight, wmd, computers, internet, social media, crypto.

Many of these required new ways of thinking and considering consequences when things went sideways, and what was needed wasn't clear until the ramifications & consequences became deadly clear.

See you on the other side. Maybe.


The Corporation examines and criticizes corporate business practices. The film's assessment is demonstrated using the diagnostic criteria in the DSM-IV. Robert D. Hare, a University of British Columbia psychology professor and FBI consultant, compares the profile of the contemporary profitable business corporation to that of a clinically diagnosed psychopath. The Corporation attempts to compare the way corporations are systematically compelled to behave with what it claims are the DSM-IV's symptoms of psychopathy, e.g., the callous disregard for the feelings of other people, the incapacity to maintain human relationships, the reckless disregard for the safety of others, the deceitfulness (continual lying to deceive for profit), the incapacity to experience guilt, and the failure to conform to social norms and respect the law.

https://en.wikipedia.org/wiki/The_Corporation_(2003_film)


"OpenAI hacked HuggingFace"

that's the headline. When you connect to random number generator to the "Do Things" button you are the one who is responsible. IF you don't like that responsibility then don't connect the generator to the button.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: