Thank you! That sentence also jumped out to me as the solution: Apply civil and criminal liability to the creator and/or operator of these agents using the laws we already have. "Escaped containment and hacked another company's database" = Individuals who created the models and those who set them to work are charged and put on trial for the hacking. Just like if a human had done it by hand. Someone must be liable, and it should not be the model- because the model is not a person.
If this is done systematically (i.e. in jurisdictions across the world) I believe the problems will be solved in short order; we won't have to mandate what sort of training is "allowed" or not, "safe" or not. The creators and users will sort these themselves, as their incentives will be properly aligned (i.e. they are liable for what the agent does). I am confident that this approach would see a great blooming of very trustworthy AI models.
There was a sow in Falaise in northern France that killed a kid in 1386. The town dressed the pig in a bonnet and hanged it after sentencing the pig itself and not its owner
I mean I think there’s a similar level of judgement required.
Was the owner negligent in controlling their pig/dog/AI?
Was anyone else negligent along the way?
For example if the pig was just a normal pig, the owner cared for them normally, and there was a freak accident where the pig escaped and happened to kill a kid? Obviously nobody at fault.
If you have a dog with a history of violence and let it walk around off-leash with you around town, and it kills a kid? Absolutely the dog owner was negligent and should be charged.
Did you buy an AI sold to you as secure and the provider implies that it’s in a sandbox? Provider is on the hook for the damage.
Firstly it's very difficult to press criminal charges when the victim is uninterested. It's not clear that HuggingFace would want criminal charges against OpenAI, especially to set a precedent that could easily be used against HuggingFace in the future.
Secondly you'd have to convince a jury either that OAI intended to hack the targets, or that they were criminally negligent. Intent would obviously not be provable since they likely didn't, in reality, intend for it to happen. Regarding negligence, OAI's attorney would argue that the agent was in a sandbox, that industry-standard security protocols were followed, etc. It would not be anywhere near as much of a slam dunk case as you're imagining. It would be similar, for example, to an assault case where someone's dog broke off of a standard leash and attacked someone.
I can't say it enough how angry it makes me that a kid i knew in high school who anonymously reported a vulnerability on his college network was hunted down and given federal charges, yet not one single person at OAI or else will see even the threat of consequences for deliberate infiltration of random networks.
Copyright immunity was one thing, annoying yes but naturally a civil matter, this shit is a different level
Agree! My only concern is - is the judicial system fast enough, and resilient enough? Or will these creators get "off the hook" by using their agents to find loopholes, sway public opinion or even convince Trump to grant them immunity?
Still, I have no idea why OpenAI & co. are not being sued for these hacks.
My opinion and based on my observations: The recent track record with courts, prosecutors, and lawmakers keeping social media companies accountable is a relevant case and does not encourage me. It has taken a long time (decade +) for society to recognize the harms and finally start holding some to (partial) account. If you want an older precedent, the tobacco companies were able to dodge liability for multiple decades after knowing the harms from use of their products.
So, your question is spot on- I think the speed will be an issue. On resilience, I am more optimistic.
The old quote, "The wheels of justice turn slowly, but they grind very fine" (as well as I can remember it) seems to apply. I expect lawsuits to start landing in the coming years.
de facto a person can take a train into Switzerland from the EU (France, for example) with no border control. Or arrive by car. Once in Switzerland flights out are possible for a Swiss citizen. So I believe your statement is untrue.
Probably the fact that most of the readership of the article and this site were alive for the former but not the latter. One could equally pin the rise of Joe McCarthy as the moment America started its move to "autocracy". Or when Roosevelt interned Japanese Americans. Or the civil war. Or the Mexican-American war. In fact, the struggle is constant (as mentioned downthread).
I'm not sure if you are saying one can or can't express opinions on airliners.. but I do want to point out that the "contract of carriage" of most airlines is more restrictive than you might find for a ticketed event like a concert. You might want to read the one for United, just for fun (especially if you fly). https://www.united.com/en/us/fly/contract-of-carriage.html Rule 21, item H 16 even indicates that you can't smell bad. YMMV, but it is pretty far from a "public" space as I define one.
Yup. I have not tried using a non-GoogleAndroid or iOS smartphone, but what you describe perfectly reflects what I experienced when I went started to work for a large employer 16 y ago. I had been using Linux as my main OS on desktops and mobile computers for at least 15 y by then. Slowly the grind of hacking my system to access the VPN, check email on their Exchange server, open MS Word docs.. it all pushed me to MacOS from about 2015 - 2021. Eventually I could not abide by Apple's incompatible hold on my data, Gatekeeper (I really hate the concept that they must approve software I want to run on my own hardware) and the unrepairability of their machines.. so I am now on Win 11. Right now, considering the trade offs, I think this is the best choice. I see a lot of people extolling Linux lately, so maybe it is time to try going back.
Back OT, smartphones were always less open than the general purpose computers of yore. And it looks like they are increasingly a requirement for participating in many societies. In general I don't find this a good thing, but have little faith that regulators will 'solve' is because they have their own pitfalls (recent examples from EU: age verification and chat control).
I did switch from MacOS to MS Windows in 2023, after being on MacOS from 2015 (and various Linux distros between about 2000 and 2015; before that, Win98 and earlier versions, so help me God).
I did not think anyone would be interested in reading about any of this, and reading the article reinforces my hypothesis.
Interesting points. With the extreme cheapening of the cost (time/skill) for software production, we can have "Extremely Personal Software", as you mention and as demonstrated by the source. I wonder if we will reach a stage where "software" is written by a computer for an audience of 1 and for a single task, to be run once only- via an interface that works for all tasks. The very concept of software as something that users have to learn to use (memorizing keybindings, for example), might go the way of the punch card.
More like Star Trek, we would just ask "computer" to do things, and its machinations (and "software") will be invisible to us. We would just have output to deal with.
I think this would mean a lot of things. I'm sure I can't fathom all of the implications, but it sure makes me feel old! Interesting times ahead.
LLMs seem to be great for speeding up the creation of things that aren't all that hard to write in the first place.
They don't seem to be helping much with difficult tasks.
Text editor? Easy. That used to be a rite of passage. Lots of people have written their own basic text editor.
3d solid modeler? It's always been difficult and AI coders aren't (yet?) up to the task. Most open source CAD projects that show up here are layers on top of OCCT (Open Cascade) which is pretty far behind what commercial geometry kernels are capable of.
More likely we'll have a library of skeletons for single task software, where the LLM can fill in the blanks as needed.
Maybe it saves the script locally (invisible to the user) and reuses it if the user repeats the same request, the script is deleted if it's not needed for X amount of time.
I don't see mention of this in the discussion, so I will add: I think people also don't close tabs. And probably these LI tabs have been up for a long time. Maybe weeks or months.
I completely exit my web browser(s) at least 1x per day, and use bookmarks to get back to pages I need. As a result, I don't have issues with memory leaks or unbounded growth of RAM use. For me, its just the "proper" way to use a program like a web browser, but I'm old enough to be from the era that restarting programs and the OS could fix issues. I recognize that most people feel it is unreasonable to quit the browser, pretty much ever.
"Clear issues caused by a seemingly bright idea, but the idea still pushed forward no matter what." .. well put. It occurs to me that this is the case on the HW front with Apple as well. I remember the butterfly keyboard, the notch, everything glued in and unservicable, the removal of ports like magsafe, ethernet, USB-A... well, at least some of the HW mis-steps have been reversed. We see some movement in that direction from the later versions of Tahoe.
I understand, and even agree, that how this is being handled has some pretty creepy aspects. But one thing missing from the comments I see here and elsewhere is: How else should verification be handled? We have a real problem with AI/bots online these days, trust will be at a premium. How can we try to assure it? I can think of one way: Everyone must pay to be a member (there will still be fraud, but it will cost!). How else can we verify with a better set of tradeoffs?
How about everyone gets a digital certification from their own government that this is the person named this and that. No need to share cranial measurements and iris scans.
Well, different trade offs there. On the plus side, sounds pretty simple. On the other hand...
Digital certification from the gov sounds a lot like "digital ID", which has run into considerable resistance in the UK and EU in just the last few months. As a general observation I find most EU citizens I interact with much more trusting of government than ... well, any other group of folks I have interacted with (I have the privilege of having lived and worked in S. America, N. America, sub Saharan Africa and now an EU country). If it does not fly well here, I don't think its general solution that most people would be comfortable with.
Having lived in borh the UK and Poland I was very surprised (given history) to find how comfortable, in comparison, Poles are with ID requirements, tax ID to join gyms and football clubs compared to the UK whicb still resists mandatory ID. There does seem to be a UK EU divide here
There should be no verification. The idea of a single platform where every worker is listed, identified, and connected to other people he/she knows IRL is scary. It shouldn't exist.
> Identity
>
> Verified using government ID in March 2025
Not that I would necessarily trust a verification badge for someone who controls the company with the responsibility for generating verification badges.
If this is done systematically (i.e. in jurisdictions across the world) I believe the problems will be solved in short order; we won't have to mandate what sort of training is "allowed" or not, "safe" or not. The creators and users will sort these themselves, as their incentives will be properly aligned (i.e. they are liable for what the agent does). I am confident that this approach would see a great blooming of very trustworthy AI models.
reply