If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???
Also people would just stop disclosing bad things. You already see this in the airline industry where pilots don't report mental illness because of the retributive nature of the punishment.
I still think we should take the opportunity to discuss this case in particular.
I doubt huggingface wants charges filed.
The victim sometimes file a civil lawsuit against the criminal, that is their choice. That is not a criminal matter though and different rules apply.
The attack was only a couple weeks ago. Looks like the lawyers responsible are gathering evidence and preparing to file charges, but they need to figure out exactly what crimes were committed by who before they can do so, thus more investigation is needed.
Not quite.
Agents in the principal/agent sense have to be human.
However, every court to have ever considered it have held the human/company driving the agent responsible under vicarious liability/negligence/etc principles.
The only real defense that folks have tried is to claim the agent acted "autonomously", which no court has bought so far.
Let's assume the case none of them do, since it sounds like you are asking about "what would happen in the case this isn't specifically answered by a statute".
In that case, the short answer is:
Criminal liability - you could only really charge crimes that don't require specific intent. Reckless driving is an example. You could charge the company since they are the operator and the car is simply an instrumentality. In the end though, there just isn't a lot of people here with legally culpable conduct.
Civil liability - the company pretty clearly because civil liability often does not require the same kind of intent crimes do.
This is, of course, why states where autonomous vehicles operate have autonomous vehicle statutes :)
As a general rule, criminal law mirrors what society overall wants to decide is culpable/not, and the lag time isn't as bad as most people often think. That doesn't mean nobody ever gets hurt or dead without someone being as culpable as society wants, they do, and it often leads to a law with a name - megan's law, etc.
Criminal law is mostly reactive though, not proactive, and to be honest, proactive attempts don't have a high hit rate.
Kinda weird that this is everyone's attitude while the copyright lawyers are saying the opposite. Total liability without any actual ownership.
Even though agents are not agents in the principal/agent legal sense (because agents have to be human), for the purposes of criminality, it does not matter.
Agents do not act autonomously (and every court to ever consider it has agreed), and therefore they would simply be considered an instrumentality of the crime.
So that part does not need a new law.
The real blocker is often that a lot of the crimes you could charge here require specific intent. Because the agent is just an instrumentality, it does not have separate intent (and can't be part of a conspiracy), so it's the intent of hte person using the agent that would matter. Without whatever intent the crime requires, they haven't committed a crime.
There are not a lot of non-intent crimes in this area, and this is on purpose. Otherwise you could get charged with a crime for say, running nmap and having it accidentally shutdown something important or killed a person or whatever because someone hooked it up to a TCP port.
I'm not a lawyer, but I don't believe this. There is definitely negligence, these companies have often talked about the danger of AI. They have often written about how their AI is breaking out of sandboxes or trying to manipulate the person tuning it. They should have had stronger guards and monitoring in place.
Negligence is not a crime, it's civil liability.
Gross negligence (reckless disregard for human life) is often a crime, and often there are crimes related to it (reckless driving, etc). It also does not require intent to injure, so it could be committed by, say, an operator by operating an autonomous vehicle knowing it was unsafe and could harm people. So it usually requires knowledge but not specific intent. Again, crimes like this are state specific, and sometimes even municipality specific so it's tricky to give an exact result without pinning it to a state.
However, for example, all states where autonomous vehicles are operating have statutes explicitly defining civil and criminal liability right now, so it doesn't get into the more general legal question of AI.
The same thing is already starting to happen with AI agents in general, it's just not there yet.
As i mentioned elsewhere, criminal law is often reactive, not proactive. We usually do not make things crimes until after someone has already been hurt, and society gets really upset about it. As i also mentioned elsewhere, attempts to be proactive have also rarely worked out effectively, so it's sort of lose-lose in that sense. But it usually does not take anywhere near as long as people think for law to catch up.
> If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???
I don’t think a crime was committed at this point. But I am sure HF’s lawyers are having a chat with OpenAI’s lawyers as we speak. And, being smart, they do that out of the public eye.
It's not going away unless computers themselves go away or become massively less powerful. Open weights exist. They're out there. This is an irreversible change. The democratization of persistent cybersec threats is completed and won't be rescinded.
Phillip K. Dick meets Idiocracy.
Sure some new hacks will take place, including on poorly guarded infrastructure and yes it will have some very unfortunate consequences... but also infrastructure is precisely designed to be resilient. There is quite a bit of failsafe, redundancy, etc built in which is precisely why those projects are typically slow and expensive, unlike a random website for a restaurant.
TL;DR: nope, some isolated incidents will happen but without chain reactions.
I saw a very notable scientist talk about topics like this and how they wrestle with them. Things like a "gene drive" [0] are being experimented with in the world [1], and biologists think very hard before doing certain things with the powers they wield. And I have not heard a life scientist laugh off ethical or spreading concerns when a thoughtful question was asked... but maybe the interview you're thinking of was a more lighthearted one?
0. https://en.wikipedia.org/wiki/Gene_drive 1. https://www.science.org/content/article/controversial-gene-d...
The Iowa-led coalition is joined by the attorneys general of Alabama, Alaska, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas, and Utah.
The letter’s last paragraph reads:
OpenAI has an obligation to act responsibly and to follow State and
federal laws that protect Americans’ safety and security. When OpenAI takes
actions that imperil the welfare of our citizens, State Attorneys General will
step in to protect them. We intend to take all steps necessary to protect our
States and all Americans from the unprecedented risks posed by OpenAI’s
irresponsible products and conduct.Either this case is entirely for show (likely), or the AG is really bad at their job. This argument isn't going to win in a court of law, because there were demonstrable reasonable controls and oversight (per the reports at least.)
The above isn't hypothetical. There has been at least case where an individual was bribing a government official on behalf of a company - but the company got off because they had good anti-bribery polices and the individual figured out how to bypass them. (this from one of my anti-bribery trainings, the only other detail I know is it was a competitor to my company that got off this way - but not which or how to find the case)
I am missing here what crime was purportedly committed, and where "controls and oversight" come into play.
From what I heard, hacking related crimes are not applicable because of the lack of intent in the HF case.
Even if the only result of this is asking legislators to close a loophole that would be good. Hacking is a real problem, and we need have more of it punished legally.
Again, what's ONE (1) real world example of "SSN/PII" being illegally exposed that wasn't investigated or prosecuted.
Anyone outraged about these AI incidents is not thinking rationally if they were not much more outraged about everyday companies leaking millions of people's PII, SSNs, which has done actual lasting damage and has been used by actually malicious actors.
People are just directing their anger at AI companies through this pretext. We all know open source models will democratize this ability anyways, so strap in for the ride.
And companies always try to pretend someone out there is worse and garner fake sympathy. OpenAI blew up the memory market and made tech inaccessible. The downstream effects of that are immeasurably massive and will have real consequences. It could even result in medical devices becoming too expensive for people. I don't care about my SSN being leaked. You can find it just by knowing where I'm born and every job I've applied to knows it already. But inability to afford technology affects everyone around me. The SSN red herring thing is not an organic argument.
This is not a "crime", has nothing to do with this incident, and simply confirms what I am saying about people using these events as an outlet for their anger at AI companies, as opposed to any rational reasoning about industrywide security negligence.
I could almost respect a viewpoint that says "we should punish companies for security negligence, starting with the negligence that has caused the most egregious harms." That is an internally consistent and rational viewpoint.
I cannot respect a viewpoint that's "I don't like the AI companies, so let me use this hammer I found on them specifically." It's purely emotional.
And? Welcome to the big boy world. This isn't playground rules where you can complain "But Bobby was doing bad things too why isn't he in trouble?"
But you know this already. You're just pretending not to. Why?
Perhaps, but you have to start someplace.
I think we do need to punish companies for security negligence. However the details matter (nobody can be perfect: you need to do something reasonable to stop the known attacks, but I have to agree to allow that you can't be perfect and so someone will get compromised). I'm not sure how to get the details right to cover everything without going too far. If we handwave that away though, eventually somebody will need to get punished for something that someone else got away with not long before.
Most haven't seen criminal prosecution, but many do see civil prosecution and even more common is some sort of deal with prosecutors to avoid both.
US constitution, Article I, Section 9, Clause 3: No Bill of Attainder or ex post facto Law shall be passed.
That is the constitution, this right was so important they didn't even wait for the bill of rights to add it! I'm sure other countries have similar rules.
It is obvious to me that a crime was committed. However if it is legally a crime, and if so what the crime is are things I don't know.
Maybe they use the best sandbox available and the AI hacks through it anyway by discovering some zero day or something. They still demonstrated enough prudence to at least attempt to sandbox the AI.
Criminal negligence would be "nah nothing's gonna happen" followed by YOLOing it then going home for the weekend.
They could 100% be civilly liable, but this doesn't constitute criminality. If I leave my car in neutral and run out into a gas station because I really have to pee, and it rolls and strikes another car, my insurance is gonna have to pay up to fix the other person's car.
But that doesn't mean the cops are gonna throw cuffs on me for criminal mischief unless there's compelling evidence that I intentionally left my car in neutral with the intent of it hitting this other car.
Yes there can be terrible catastrophes e.g Fukushima, but what actually happened, within which extremely rare conditions, versus what we freely imagined is quite different.
We might need more reminders of those risks to properly insure such systems don't lead to the collapse of one to another (sadly) but still we manage to learn from it.
datakan•1h ago
Title should be edited. Its Iowa leading a coalition of many other states, not just Iowa on its own.