Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
> If you don't want to suffer from it, you're going to have to find much better defense measures.
So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.
> So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
I'm not the person you're responding to, but...
If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.
1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...
If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?
I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."
But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?
ETA: and furthermore, what crime is worse? And should it be?
He probably cares more about still having a laptop.
What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.
Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.
However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.
Truly no place I'd rather be.
This is what the politician in question said:
"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."
Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.
That is what I'm getting at.
OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.
While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?
The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.
I don't disagree with you - but I am curious as to the amount of power and effort that goes into something like this. I suspect that these hacks into systems are carried out by many agents, running on many MW of compute for a long time - how many actors have access to resources like that ?
In the OAI case where we can easily treat it as a law enforcement action, that's a far cry from "who cares who's liable." If the OAI case can be a law enforcement action, we're on the same page. The fact that sovereign nations don't land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I'm commenting on.
There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.
I saw an analogy recently.
If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.
OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.
How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?
If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )
Yes, this is why all discussion about "safeguards" is maddening to me. They are simply committing crimes, and people should go to jail. I guarantee that OpenAI will stop worrying about "alignment" when people simply go to jail for hacking and theft.
Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?
Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"