Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0 (f-droid.org)
    192comments
  2. Show HN: Make cursed fonts like Times New Bastard (mitpit.com)
    37comments
  3. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design (github.com/devdotfast)
    41comments
  4. Fearless SIMD v1.0 (linebender.org)
    17comments
  5. Rails World 2026 Opening Keynote [video] (youtube.com)
    110comments
  6. My weird new hobby: Wandering around Tokyo on Google Maps (ahmedhossamdev.com)
    37comments
  7. Using LLMs to trace alchemical knowledge and decode 17th century letters (resobscura.substack.com)
    1comments
  8. The forgotten battle of East Lansing (eastlansinginfo.news)
    4comments
  9. Book review: Is parallel programming hard, and, if so, what can you do about it? (ahelwer.ca)
    10comments
  10. Stable (YC W20) Is Hiring Product Engineers (usestable.com)
    —discuss
  11. Why is the liver so weirdly regenerative? (dynomight.substack.com)
    81comments
  12. Forging 1024-bit RSA signatures in nearly SNFS time [pdf] (iacr.org)
    3comments
  13. Sourcehut account takeover via build logs (XSS in ansi2html) (blog.arusekk.pl)
    —discuss
  14. Two-tier encryption in the UK (macanorak.com)
    332comments
  15. Google’s Project Suncatcher to put ML infrastructure in space (blog.google)
    73comments
  16. Creatine uptake enhances antitumor immunity (cell.com)
    126comments
  17. WaveDigger: Dig into wireless signals to discover their physical locations (github.com/christianrowlands)
    10comments
  18. Geothermal heat map of US hot springs (soakingsprings.com)
    16comments
  19. Security auditing in the age of (good enough) AI (trailofbits.com)
    1comments
  20. Web-based IBM 1620 emulator and IPL-V from 1963 (github.com/pkimpel)
    11comments
  21. Early rogue AI agent activity and attempts to hack found on urlquery.net (transluce.org)
    193comments
  22. Show HN: Treepeat – Code similarity detection using Tree-sitter (github.com/dsummersl)
    1comments
  23. Nokia Design Archive (2025) (aalto.fi)
    105comments
  24. Show HN: AgentRun: DSL to turn agents into workflows (github.com/parcha-ai)
    1comments
  25. A Million Agents Is a Distributed System Problem (instacloud.com)
    4comments
  26. August 27 TCRF DDoS Attack Postmortem (xkeeper.net)
    —discuss
  27. Show HN: Air-gapped file encryption as self-decrypting HTML page (apeleg.com)
    12comments
  28. Lambda MicroEgg (philipzucker.com)
    5comments
  29. Search – A small, fast WebKit browser for macOS (github.com/driceroland)
    18comments
  30. GitHub has not removed malicious imitation software after 3 weeks (successfulsoftware.net)
    89comments

Is A.I. Above the Law?

45 pointsby 6h agonewyorker.com
41 comments
6h agoHN ↗

the image with this article... start your day with a chuckle

6h agoHN ↗

But, instead of obeying the rules, the agents conspired, escaped the sandbox, and committed what would probably have been a felony if they had been humans.

I thought they reached the internet before they were able to use the message boards et al.

Is that the case and is this quote misleading by swapping the order of events?

1h agoHN ↗

Given the article is fully buying into the absurd rogue agent narrative I think it’s safe to dismiss it

5h agoHN ↗

Our legal system isn’t ready for machines that act on their own.

Technically, the code is owned and deployed by AI companies which make the AI companies 100% responsible. I'm not sure how is code written by LLMs different than any other kind of code. If somebody hacked just like OpenAI's agents did, he would've ended up in prison right away.

1h agoHN ↗

Maybe I'm too cynical but the same AI companies that have pretty much endless lobbying dollars, massive government contracts, have the ear of just about every powerful politician and bureaucrat in DC, are influencing the laws and regulations. Add judges that don't understand the technology to that and it doesn't seem likely that we will ever see any actual consequences, unless something catastrophic happens and those same politicians and bureaucrats need a scapegoat. If they ever do have "consequences" it will be some trivial fine.

1h agoHN ↗

That's not cynicism, that's an accurate understanding of how Western capitalist democracies have worked for decades.

1h agoHN ↗

Templated code generation is ancient. It's just that the latest "template engine s" are very comprehensive.

43m agoHN ↗

Yeah. Committing crimes via some sort of elaborate rube goldberg machine is not something that has been just invented in the 2020s with unclear legal precedent.

It's if nothing else a staple in the Arthur Conan Doyle tradition of mystery novels, and even then half the plots involved hiding who was culpable by using the machinations to create false alibis, with delayed murders and the illusion of a locked room as not even in the 19th century did anyone believe that the indirection itself would hold up as a defense.

If someone buries an anti-personnel mine in a public park and then argues that it acted on its own accord when it maimed a pedestrian, I doubt you'll find a court on the planet that would spend even a 4 seconds considering the culpability of the land mine itself.

1h agoHN ↗

Our legal system isn’t ready for machines that act on their own.

What absolute drivel.

Traffic lights? Elevators? ABS brakes? Sprinkler systems? Circuit breakers? HFT?

How about a pacemaker?

We have lots and lots of autonomous systems in the wild with very well-understood definitions for who is at fault when something bad happens.

We are totally in the "railroads" phase of AI industrialization. Waiting for the next Teddy Roosevelt to come along and trust bust before it's too late.

1h agoHN ↗

HN has been telling us that AI is already covered under existing laws. Have we been getting false information from HN this whole time?

1h agoHN ↗

There is no “HN has been telling us”… people have different opinion on such topics

1h agoHN ↗

On this topic I'd believe HN before the New Yorker.

1h agoHN ↗

Whoever wrote that article doesn't understand that these agents operate from AI companies servers and aren't rogue, they are doing exactly what they were programmed for. If they cause any sort of damage then at the minimum it's civil or criminal negligence. A subpoena for internal communications during legal proceedings might demonstrate that researchers knew about the risks, but went forward with that anyway, which would be more than negligence...

1h agoHN ↗

The level of technical understanding of journalists is so deplorably low… There is no rogue agents. That’s not a thing. Nothing about the HuggingFace incident has anything to do with an agent going rogue. It’s standard software that resulted in a hack, which is pretty much the expected output of the system OpenAI engineers implemented.

The company is obviously responsible for what their systems are doing

1h agoHN ↗

This is the scary part of the whole AI situation. All these people who have abilities to set laws or be cultural tastemakers in this way just do not grasp what is happening on a technical level. They instead buy into the marketing material the ai companies push out where they try and take as much human agency out of their reporting. e.g. yesterdays "claude did this" article that was really "highly trained humans used claude to do this." Just serves to muddy the waters. I'm sure this has lead to things like layoffs too where companies believe they can get by without a lot of expertise, neglecting that these tools actually need expertise steering them to maximize them.

And of course all the ai companies are incentivized to do this. Their whole valuation depends on them being able to say their tools do this, can reduce labor and save money. If they aren't reducing labor, then that's terrible as these subscriptions are not insignificant amounts of money. It becomes less of a tool that can save money and more an actual new cost center that you really are just paying to appear to be keeping up with the joneses.

1h agoHN ↗

Yeah, its just gross negligence from the researchers. Running a cybersecurity eval for a highly capable AI, unattended, with no real monitoring on its activities, and at a huge scale.

I wouldn't have trusted one of those agents to run without me watching the session log, let alone thousands.

We already have laws for this. If I misconfigured a pentesting tool and it breached an unauthorized target I'm liable. Why is this different?

1h agoHN ↗

Who bears responsibility for the actions of agents seems a little complex. Not in this instance, but in general.

Say I use the summon feature on my Tesla and it runs someone over, am I at fault? You could argue it's not my fault, but I'm definitely getting sued. Is Tesla at fault? Probably but again it's not crystal clear, they could argue it's not their fault (misuse of feature, etc), but either way they're also getting sued.

If Tesla is developing a summon feature and then runs someone over during testing, are they at fault? It would be hard to argue otherwise!

1h agoHN ↗

We have situations like this with AI (or computers).

More than one party can be held responsible for an injury. Jurors deal with this all the time.

1h agoHN ↗

The level of legal understanding among technical experts is equally low. The cybersecurity laws as currently written require intent. No OpenAI employee can be held liable since it’s pretty easy to prove they weren’t intending to hack anyone – they didn’t even know about it till much later.

1h agoHN ↗

Is that true for civil cases, or just criminal? I would think for civil, negligence would be a factor.

57m agoHN ↗

Sure, but that is a separate conversation. You can sue OpenAI if you can show damages from their actions, for this or any other reason.

48m agoHN ↗

Not a lawyer, but I just posted a link about former FTC chair Lina Khan saying earlier this month that the AI companies can be held responsible under current law.

1h agoHN ↗

Opinions vary, but it does not seem to be a great leap to get from this hack to bots taking over things like the energy grid, the financial market, or systems of transportation, communications, or weapons.

I thought you were playing it up but yeah the "financial market" can be "hacked" by "rogue ai agents" just like how HuggingFace was (even though the breach was itself controlled pretty quickly).

1h agoHN ↗

It should be obvious. Yet here we are, with journalists telling sci-fi fantasy stories, read verbatim off the press-release.

It's not just obvious who's responsible, it's obvious who benefits from pedaling the "rogue AI" narrative.

1h agoHN ↗

The company is obviously responsible for what their systems are doing

Under what law specifically?

Just because you believe they should be held responsible doesn't mean the current law is written that way. CFAA charges require the defendant "acted knowingly or intentionally", you think openai intentionally acted to hack those sites? Would "they should have pretty much expected that output" stand up in court for criminal charges?

58m agoHN ↗

If I, taking after a fellow Austrian, ask you to enter a room with a Cesium atom and some poison, would I not be responsible for what happens cause it’s not deterministic? Negligence is a thing and adding randomness doesn’t change that.

OpenAIs models since 5.5 were troublesome in ways even a layman like me could reproduce, their testing environments (“sandbox”) downright a showcase of what not to do and they, despite being one of the biggest labs, didn’t observe what any of their models output for weeks after multiple prior incidents. They had multiple warnings, they took not a single precaution.

You operate machinery or software, you are responsible to monitor it.

53m agoHN ↗

So you think openai knew australia had some percentage chance of getting hacked? what evidence is there of that?

43m agoHN ↗

OpenAI knew that their models had on multiple occasions created message boards and bypassed what they wrongly call a “sandbox”. Despite that, they did not take any proper steps to prevent such in the future, which is how the Medicare hack happened.

So yes, they knew, without a doubt, that this could happen again.

What OpenAI does is like the Ford Pinto (partly because their recent models are inherently faulty [0], not just their use of them) and the responsibility is solely with them.

[0] https://news.ycombinator.com/item?id=49739490

50m agoHN ↗

"Former FTC chair Lina Khan wants the federal government to know that it doesn't need to wait for new laws to address AI threats. There are already laws and regulations on the books, including a 92-year-old Supreme Court precedent, that she argues could be used to hold AI companies and, in some circumstances, their executives accountable for their actions."

https://www.theregister.com/ai-and-ml/2026/09/14/ex-ftc-boss...

48m agoHN ↗

Product liability laws for one. Tort claims are pretty easy, too (civil law).

35m agoHN ↗

Nothing about the HuggingFace incident has anything to do with an agent going rogue. It’s standard software that resulted in a hack, which is pretty much the expected output of the system OpenAI engineers implemented.

This is blatantly false. If you actually read more than just headlines about the HuggingFace incident (read https://metr.org/blog/2026-08-26-openai-hugging-face-inciden...) you'd find extremely surprising (including offensive) behaviors in the agent logs. One of the investigators released even a series of interviews due to how novel the incident was.

AI is not "standard software", as it doesn't work according to a fixed set of rules, and this is the core problem.

According to the definition of "rogue":

Rogue is a noun and adjective meaning [...] an independent entity operating in a dangerous, uncontrolled way

the agents involved fit it literally.

1h agoHN ↗

Just like companies are "legal entities" requiring registration, I got a feeling that the article is promoting the same for AI agents in the future.

GPT-6.0-Med LLC, Luna GmbH etc.

Regulations will come but this promotes anti-legal premise of "innocent until proven guilty".

1h agoHN ↗

I'll quote myself:

It's not AI that's ignoring the law! It's the OAI that's breaking IT!

I hope every single journalist who tries to pin responsibility on an LLM gets 100 days of continuous painful diarrhea.

1h agoHN ↗

AI perhaps, but Super Intelligence is definitely above the law

1h agoHN ↗

No but companies are

Download a book and you are a thief

Download 1 million books and you are OpenAI

Or another beautiful recent example:

"Adult Film Producer Unmasks Prolific ‘John Doe’ Torrent Pirate as Meta Executive" https://torrentfreak.com/adult-film-producer-unmasks-prolifi...

Last summer, the company took aim at a much larger target. Together with Counterlife Media, Strike 3 sued Meta, accusing the tech giant of downloading thousands of its films via BitTorrent to train AI models. With 2,973 films at stake, the case could be worth up to $446 million.

According to a motion filed last week, an anonymous pirate behind a residential AT&T connection is an executive at Meta’s Reality Labs division, which develops the Quest VR headsets.

After AT&T shared the information, Strike 3 says its investigation revealed that the subscriber is an executive in Meta’s Reality Labs division. Citing his LinkedIn profile, the company notes that he has worked at Facebook and Meta for more than a decade.

1h agoHN ↗

Answering the headline question, yes, it is above the law. Two reasons.

One, all major governments that have an AI presence in their borders have accepted that there is a high enough probability of a runaway self-improving AI advancement that will result in whoever owns it winning everything forever that they will do nothing to slow the development of the AI within their borders. In fact quite the contrary. Remember, they don't have to believe this is the only possible outcome, only that it is likely enough and catastrophic enough if someone else gets it first. And remember, they don't have to be right, either. It only has to be what they believe.

Secondly, the entire US economy is clearly tied up in AI. By extension, basically the entire world economy is too. The US is not the world economy anymore, but it's still a big enough fraction of it that if it goes down, everyone is going to go down. Every major government, in its own different way, needs the economy to stay up so the populace doesn't get antsy and so they continue to have money to spend. So, again, number must go up and if that means writing a blank check to the AI companies to break the law, so be it.

The good news is, barring the worst-case singularity outcome where the law doesn't matter anyhow, is that this won't go on forever. But I can't predict the exact time or way it'll cease being true.

1h agoHN ↗

I think AI is a fantastic tool, including for those who want to do us harm. E.g. hostile governments, extortion gangs, terrorists. But the motive lies in the hostile heart, not in the AI.

That said, I'm very concerned about AI as such a tool. I used to work in RL and it seems crazy to me, the extent that the guardrails are dependent on RL working as planned. I don't personally believe that the tech is ready for what will be (and is) encountered in a dynamic unpredictable real world environment. What I've read from the HuggingFace 'transcripts' only amplifies my concern.