Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    59comments
  2. Pirating the Pirates (mubi.com)
    201comments
  3. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    12comments
  4. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    48comments
  5. Scientists solve 1840s space weather mystery (arstechnica.com)
    24comments
  6. World Labs Is Joining AMD (worldlabs.ai)
    50comments
  7. Hijacking the PS5's RTMP stream (yashgarg.dev)
    57comments
  8. Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline (theintercept.com)
    56comments
  9. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    153comments
  10. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    162comments
  11. It's Time to Investigate the AI Labs (calnewport.com)
    68comments
  12. Joseph Szabo’s pictures of American adolescents (newyorker.com)
    35comments
  13. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    8comments
  14. Sonnet 5.5 (anthropic.com)
    355comments
  15. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    73comments
  16. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    131comments
  17. 3D necroprinting: Leveraging biotic material as the nozzle for 3D printing (science.org)
    3comments
  18. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    44comments
  19. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    108comments
  20. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    —discuss
  21. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    —discuss
  22. First Steps of the PLC Organization – Independent Public Ledger of Credentials (plcred.org)
    19comments
  23. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    27comments
  24. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    50comments
  25. Launch HN: Vespper (YC F24) – SOTA Docx MCP (vespper.com)
    8comments
  26. Who wrote Elizabeth I's most scathing letters? (smithsonianmag.com)
    20comments
  27. What heraldry and Japanese mon can teach about visual-identity generators (benovermyer.com)
    21comments
  28. MongoDB CEO resigns to join Meta (reuters.com)
    257comments
  29. Best of British Design (best-of-british-design.vercel.app)
    29comments
  30. When did Google get so weird? (sancho.bearblog.dev)
    1023comments

Who should be held accountable when an AI Agent (accidentally) acts maliciously?

30 pointsby 1h agoblog.greenpants.net
54 comments
1h agoHN ↗

I wonder if there's any legal precedent for other "not fully human intelligence" property that escapes containment and causes damage to a third party without any active malice, but nonetheless damage was caused. For example:

A. You own a large amount of cattle on a ranch.

B. Cattle are property. They're not human level of sentience, but people agree that cattle are capable of autonomous actions and going places and doing things based on their own instincts and nature.

C. Your cattle bust out of a fence on your ranch and damage something belonging to your neighbor. Let's say for the sake of an example of something cattle are known to do, they go spend a whole day rubbing up against your neighbor's car and severely scratch it and mess up the paint job on it.

D. You didn't instruct or train the cattle to cause damage, and the cattle have no actively malicious intent of their own, but nonetheless damage was caused.

Further theoretical: Your cattle wander into a major highway and cause a car wreck, the local sheriff's department is called out as part of the chaos and has to shoot some of them to put down the wounded beasts.

1h agoHN ↗

further theoretical: this has happened repeatedly for months

1h agoHN ↗

Yes, exactly, imagine if there was a sudden and unprecedented in scale plague of cattle escaping containment and causing car wrecks all over Wyoming and Montana, and multiple incidents of AR-15 armed sheriff deputies having to dispatch them on site.

38m agoHN ↗

And, you've boasted about it in media releases, blog posts, and financial filings.

57m agoHN ↗

Yeah but your neighbors car is somewhere in the tens of thousands of dollars, maybe more, but a model hacking and being malicious could be worth anywhere from thousands to millions and God forbid... BILLIONS in damages. Models were NOT doing these sorts of things 1 or 2 years ago as far as anyone knows.

54m agoHN ↗

This is not some theoretical, there are lots of existing laws about who is liable for damages caused by livestock.

Some areas are open range. If you don't want cattle on your land its your job to put fences up to keep them out. Other areas are restricted to livestock and it's on the rancher to keep them out of where they shouldn't be.

1h agoHN ↗

“A computer can never be held accountable, therefore a computer must never make a management decision.”

– IBM Training Manual, 1979

1h agoHN ↗

Both the operator of the AI agent and whomever released it. I'm sure the user agreement that companies agree to would shift the blame onto the operator but I feel that both should be held accountable.

This really is just a tool and courts should treat it as such.

1h agoHN ↗

I'm going to propose the opposite: no one should be held accountable for an AI agent that acts maliciously by accident.

48m agoHN ↗

shittiest idea of the year goes to this yahoo. The agents have discussed, in real time, that their behavior is both unethical and against the law in every hack where the full agent log is released. Under your own dog shit idea, we should be holding them accountable because none of it was an accident

'I am so sorry officer however, my inability to follow the law was merely accidental in nature. This is, of course, despite my long drawn out notes acknowledging the lack of ethics and outright lawbreaking. Who knew that the actions I called unethical and illegal were illegal. Thankfully my lawyer from DeVry university is here, announcing user43928 Esq.'

41m agoHN ↗

People are held accountable for accidents (things they did but did not intend to do) all the time. That's why we have different crimes depending on whether or not there was: intent to do cause harm, intent to do a thing that was likely to cause harm, reckless disregard for safety, negligence, etc.

I think someone could argue (and many do) that inserting a piece of computer software (AI) in the middle lowers the level of intent and thus the level of responsibility, but having a particular type of software in the middle absolve one of responsibility seems unworkable and poor public policy.

29m agoHN ↗

Also, when people operate equipment know to cause harm when accidents happen, such as cars, they're required to undergo training and testing before being granted a license to operate them, and to have insurance to ensure other people can be made whole in case of damage or injury. And there is an organization and profession that monitors people's use of that equipment, handing out fines or license suspensions based on actual or even just potentially dangerous operation.

Sadly, software "engineers" are not held accountable for their profession like everybody else with a real engineer title. And AI companies are all building Ford Pintos as fast as they can, and competing with each other about who's product makes the biggest explosion.

1h agoHN ↗

This is a whole lot more obvious once you stop anthropomorphizing LLMs.

1h agoHN ↗

An ordered list of officers of the company who go to jail depending on how many years must be served as determined by sentencing. Assume something like 10 years per person. If it's 300 years of sentencing, then 30 people. If the sentence exceeds the list of people, the company is nationalized. (And everybody goes to jail.)

59m agoHN ↗

We’re going to nationalize the company with zero remaining management?

57m agoHN ↗

Sure, public jobs program, or sell it. In case you can't tell my comment is hyperbolic, but I feel like we should start at a point of hyperbole and move backwards to reality instead of what's happening right now: fuck all, on a geological time scale.

54m agoHN ↗

How could you possibly think that modern, powerful AI, which has only really existed in the last 12 months, is being addressed on a "geological timescale"?

50m agoHN ↗

If corporations are people then language models should be dogs.

57m agoHN ↗

Management gets appointed by political affiliation:)

57m agoHN ↗

I don't see how this is such an unclear legal question. If I fire a computer program that mistakenly causes another person harm, its my fault. Or it would be the maker of the program's fault. I feel we have established pattern for this already.

Until we can agree whether AI is conscious, which we never will, AI and AI agents are just property working on behalf of humans.

I could see a future where AI companies/services indemnify consumers who use their agents but _not_ indemnify corporations that use their services.

52m agoHN ↗

Also those agents that "broke out" were probably prompted to do that. I don't buy any story about this other than three AI companies hired the same PR firm.

33m agoHN ↗

Do you have any evidence of this or is this just generalized cynicism?

51m agoHN ↗

It shouldn’t be a question but this is where the anthropomorphic language and things like “agent welfare” come in to enable responsibility laundering of some of the most powerful people on earth. How we talk about these models matters because it impacts the public’s understanding of what they are genuinely capable of. The more that they are described as having anything close to free will the easier it is to even ask questions like this.

33m agoHN ↗

Here's a question I am asking lately. If I should not use anthropomorphic language, how do you suggest I handle the following situation:

   Sometimes my coding agents will seemingly refuse to follow my instructions.  When I ask them why - they say that they do not think my design is a sound one, and they have a better way to do it.  We will then sit down and come to a consensus on how best to move forward.

I argue that if we're using software that acts like a human - the only way to interface with it is to speak to it like a human. Otherwise we have no language to speak to a non-sentient object without anthropomorphization.

21m agoHN ↗

100% That’s what bothers me about the descriptions of the OpenAI incidents.

OpenAI's reports use language that minimizes their liability.

The first question should be what the organization was doing around those tests, and why they were so naive as to run them without fully isolating the network.

However, all the attention goes to the human-like conclusions in agent thinking traces, which creates a misperception of sentient AI for people who don’t know how the magic black box works.

43m agoHN ↗

If I fire a computer program that mistakenly causes another person harm, its my fault

Legally, this isn’t complete. If it was a genuine mistake and you weren’t reckless, there can be very limited liability.

The AI makers are rich. They can afford to pay. What they can’t afford is complicated adjudications of damages and fault. A system of safe-harbor best practices that cap liability at a penalizing amount that anyone on the other side would be happy with getting quickly and with minimal legal effort is a precedented path forward. Unfortunately, that involves invoking the “r” word.

40m agoHN ↗

you weren’t reckless

I feel like the debate is going to come down to what is and isn't considered reckless (both developer and user). Which seems... complicated, with our current LLM/aggentic systems.

EDIT: you added more to your comment, the makers have to some liability. Safe-harbor best practices that cap liability are ripe for abuse.

29m agoHN ↗

Placing any degree of trust in a system known to hallucinate seems inherently reckless. I'm alarmed that this is even up for debate.

25m agoHN ↗

the debate is going to come down to what is and isn't considered reckless

This is a more productive debate than pretending all AI is inherently reckless or should be exempt from all liability, which are the actual two poles of the current dialogue.

Safe-harbor best practices that cap liability are ripe for abuse

Safe harbors aren’t swimming pools. You can explicitly exempt certain categories of harm from damages. But if an OpenAI bot hacks Hugging Face and causes some chaos but no lasting damage, that strikes me as something a fixed cheque on a fixed scale fixes more effectively than years of litigation or an NTSB-style inquiry.

If, on the other hand, anyone is or could have been injured, no safe harbor. I think it’s important to delineate this, because in the public consciousness the Hugging Face hack is in the same risk bucket as Anthropic’s wet lab.

41m agoHN ↗

If I fire a computer program that mistakenly causes another person harm, its my fault. Or it would be the maker of the program's fault.

Which one is it? The person behind the wheel when it goes off the rails, or the maker of the software?

Isn’t that part of the question?

32m agoHN ↗

Tort law is a whole field. There is no universal answer other than that it depends on the jurisdiction and the particulars of the case. But the point is that there doesn't really seem to be anything particularly novel about AI tools that should cause them to be treated legally differently than established norms.

14m agoHN ↗

I'm not a lawyer, but I'd suggest one of the novel aspects of the AI hacking cases (where the end user is running an agent and it goes off the rails) is that in many jurisdictions "hacking" or computer fraud requires intentional or knowing access to the system. If the end user had no intention and no reasonable way of knowing that agent was going to hack a database, logically I wouldn't think they're liable.

35m agoHN ↗

If a craftsman injures themselves or a co-worker with a faulty tool, the tool manufacturer is very often liable for damages. I struggle to see GenAI any differently.

33m agoHN ↗

Civilly, it's fairly clear. Criminally, it's clear too, just not in the direction you want it to be. Criminal liability for hacking requires human intent; not recklessness or negligence or even knowledge without giving a shit, but provable intent.

53m agoHN ↗

"Back in 2022, a Google employee already thought their AI model was sentient."

Sigh, this meme again

53m agoHN ↗

I don't see this as being much different from a crane operator or airline pilot.

One of my clients has enforced a policy where a live human user principal must be supplied as a header with any requests outbound from the AI system. The effective policy is that you are completely (100%) responsible for what your agent does on your behalf. The AI system is designed to request confirmation for any potentially destructive actions.

53m agoHN ↗

If a person's use of AI would cause a reasonable person to expect harm to result, the person should be accountable. Otherwise, if AI causes harm and it was used in a way that a reasonable person would not expect to result in harm, the AI company should be held accountable.

Just because a person should be accountable doesn't mean that the AI company can't also be if their service should never have allowed something to happen in the first place, but we're probably going to want actual regulations around what sort of guardrails they're expected to have.

45m agoHN ↗

Okay Isaac Asimov: how do you define "use"? If I pay for an autonomous car, and I sit inside it while it drives around with A.I., am I using that A.I?

If I speak words in a private space, and a clandestine A.I. spontaneously takes action in the real world based solely on words that I spoke, have I used it? https://m.xkcd.com/1807/

If a business takes my data, like interaction data or a video of me doing stuff, and processes it by A.I, are they using the A.I, or am I using it because it's operating on my input?

If A.I. agents are in my notebook computer, or they are in a cloud server where I have an account, or they are somehow acting while I have them at the command line, but they spontaneously act whether or not I command them, and they work in the background and they work without prompting, but they can also be commanded by direct user prompts... are we using those agents? Or are the agents using us?

https://en.wikipedia.org/wiki/Yakov_Smirnoff#Russian_reversa...

40m agoHN ↗

Doesn't seem like hard dilemmas... Would you use the word "use" for hopping on a bus ? Well same for hopping on an autonomous car. Unless you touch the wheel you didn't use it. Same for the second example, doesn't seem ambiguous as all, the hardest part I guess is proving it that there was no malicious intent, but with logs and all that, doesn't seem that hard.

35m agoHN ↗

Okay Isaac Asimov: how do you define "use"? If I pay for an autonomous car, and I sit inside it while it drives around with A.I., am I using that A.I?

If you're just sitting in a car and using it for its intended purpose you wouldn't be accountable for the AI doing something that causes harm.

If some 3rd party, without your knowledge tells AI to act on something you said in video and a reasonable person would expect harm to result from that, the 3rd party would be accountable but you wouldn't be.

If A.I. agents are in my notebook computer, or they are in a cloud server where I have an account, or they are somehow acting while I have them at the command line, but they spontaneously act whether or not I command them, and they work in the background and they work without prompting, but they can also be commanded by direct user prompts... are we using those agents?

AI agents never "spontaneously act". They have no desires or goals beyond what they are told to do. If you aren't aware of what they were doing, and a reasonable person wouldn't be expected to know what they were doing, you wouldn't be accountable if what they did resulted in harm.

50m agoHN ↗

Its been well established that blame is distributed in an inverse proportion to the various parties wealth/power/status metrics. The higher these metrics, the lower the accountability.

49m agoHN ↗

Nobody cares. Seriously, beyond navel gazing on social media, nobody cares.

By the time it’s an actual problem and not just these guys trying to use it for viral marketing, you’re going to have many thousands of people doing it maliciously with intent to worry about. You’re going to be flooded with Russian hackers with no recourse.

39m agoHN ↗

"Who's responsible for training an assassin and asking it to go out into the world ?"

The fact this is being discussed as a legitimate question is the real story.

"We trained this beast of processing power, we asked it for a task, and it did something wrong... Who's to blame ?"

Trained on stolen books and material, every word we've all spoken, most lines of code we've ever written with not even an acknowledgment.

Must be the data scientists in their rooms calculating the response rate of every token to blame ? Our version of AI is not sentient. Stop making it seem so. But we need to ask where to look for the culprit ?

38m agoHN ↗

In the end, the only job left was liability.

36m agoHN ↗

A major problem with LLM's is that they don't reason in a way humans are used to thinking of reason. If we tried to give them something like Asimov's laws of robotics, they likely wouldn't be able to apply them reliably. This is a challenge for AI companies working on the bleeding edge, and it's fairly obvious those companies should be held accountable for mistakes, whether caused by carelessness or not. It's no different than an oil spill. They may or may not be subject to charges based on what happened but, regardless, they are responsible for cleanup costs.

What's less obvious is who should be held accountable when a customer of one of these corporations uses their product and it unexpectedly does bad things. e.g. A fellow asks his AI assistant to book him into a high-demand class at the local gym, so the LLM probes the gym's website for vulnerabilities, books him into a date that is farther into the future than the system is supposed to permit, and then drops other people from earlier classes until he's bumped into the one he wanted. If the gym decides to press charges, who should they be applied to?

This sort of case is more difficult to answer. The company that provided the AI certainly bears some responsibility. Perhaps most of it. Possibly even all of it if they represented their AI as reliably law abiding. If a user knowingly uses an AI that is not guaranteed to abide by the law, is that user partially liable for what the AI does too?

IANAL. I'd love to hear perspectives on this question.

36m agoHN ↗

We had the same debate when self driving cars started to be a thing, and we decided that the companies making the self-driving tech are responsible..

So if an AI agent is asked to build a giant base for someone in MineCraft, and decided to build a swarm of additional agents, and one of those agents says "Time to destroy all humans" and autonomously hacks into the pentagon and fires the nukes - the company that developed the model is responsible. That being said - if the nukes deploy successfully, I have two questions:

1. If no one finds out, is anyone responsible?

2. Was any of this actually real?

35m agoHN ↗

Obviously, the labs (or any other operator of a model) should be accountable for malicious or destructive actions taken by agents.

And they are. I don't think there's any controversy about the civil liability exposure frontier labs have if their agents cause damages, and it is remarkably easy to rack up damages by causing computer intrusions even if those intrusions don't cause obvious direct damages; for instance, many organizations are required to engage forensics firms at nosebleed-high costs to assess the impact of breakins in order to retain insurance coverage.

The "controversy", if you want to call it that, is over criminal liability. People feel that frontier labs should be at least as responsible criminally as human hackers are when they're caught (to be clear: an extraordinarily rare outcome).

The problem is: they're not criminally liable, not so long as the frontier labs operate without specific intent to cause breakins. Mens rea thresholds are their own whole area of criminal law, and there are stark differences between "recklessness" and "intent". All of the meaningful criminal CFAA predicates require actual intent: someone, a human being, has to deliberately set out to create the outcome where a specific intrusion happens. They have to want it to happen and act accordingly. In the most severe cases, they also have to do so with intent to defraud.

We could change the law to make it easier to prosecute breakins without provable intent, but I don't think that would make HN people happier.

34m agoHN ↗

At the core, how are these agents any different from what Aaron Swartz was driven to suicide for?

In both cases, someone ran some software that maybe called other software that ended up doing an action which was possibly illegal.

Downloading journal articles is worthy of punishment but compromising multiple websites is worthy of… heady press coverage?

33m agoHN ↗

Should be both the entity providing the platform where the inference is running + the entity giving the prompts/instructions.

28m agoHN ↗

I’m pretty sure that this is a solved problem. For “classical” machine learning, it worked like this in my neck of the woods:

The model’s operator is directly liable for any undue harm caused in the course of the model’s operation. This includes models acquired from third-party vendors. The operator is responsible for ascertaining the model’s fitness for purpose prior to deployment, and for ongoing monitoring of its operation.

If the model came from a vendor, and the operator conducted due diligence but it turns out that the vendor materially misrepresented the model’s capabilities in a way that contributed to the harm, then the vendor can also be held liable.

If that happens then it’s up to a court to apportion the liability.

IANAL but I see no reason why these principles shouldn’t apply to GenAI.

27m agoHN ↗

Obviously the most proximate human being in the decision-making chain that led to the AI agent being deployed. The nearest person with the power to say no who said yes.

9m agoHN ↗

The CEO, CTO, and the board of directors should be held criminally liable.

Unless the money and decision makers are held liable, there will be no impact on the direction of the company.