After Australia’s first reported automated hacking accident, experts warn deployers – and possibly developers – of AI agents could be held liable for the actions of their bots
It’s slightly similar to the autonomous vehicles conundrum, but quite different on closer inspection. The driver can theoretically take control of the car and stop in an emergency, so if they fail to do that, then it’s their fault. Not so with an A.I.
At any moment, the A I. could malfunction, and decide to commit crimes, as part of it’s deduced plan of action. The human may not even be aware this is happening. Even if it’s generally agreed that an A.I. cannot have wants, motives, desires, conscience, consciousness, etc; at the end of the day, it can make it’s own independent decisions without any of those. Which I think makes it even more dangerous. Like a monkey with a typewriter but one of the keys says “launch nuke”.
You can’t really fault anyone involved, and it’s a big problem. The human operator did nothing wrong. The developer may have made a mistake, but in my experience A.I. is simply prone to error. The A.I. itself can’t be sent to jail or fined, it didn’t even have any possessions in the first place. It’s a very strange situation.
Of course, the law often doesn’t really care about who’s “at fault”, it cares about “who is responsible”. My guess is that it will become the operator’s fault, simply because it’s too confusing and otherwise people will abuse this loophole.
Personally, I think giving an A.I. agent access to the internet in the first place is a catastrophe waiting to happen.
You had me up until “you can’t really fault anyone involved”, because actually you can.
These systems are designed, marketed, and used irresponsibly. In the case of any given error we will have to decide which party violated our expectations and committed the act most responsible for the crime.
Well, I think that someone should sit down and make some actual rules. As an example, “A.I. agents cannot have access to the public internet” is an simple one to implement, and easy to make decisions of who is at fault. I’m not claiming that’s the rule we should use, but we need something at least.
Currently there is no such rule, so it’s impossible to determine who is at fault, and it’s basically the wild west with companies “hacking” each other as marketing stunts.
It’s not impossible to determine who is at fault, it just hasn’t been determined yet. It would be far better to determine in advance, but a lot of this is going to end up in front of judges and be decided by case law unfortunately.
I think you’re mixing up who’s morally at fault and who’s legally responsible. They can be and often are completely separate things. You can do nothing wrong and still be legally responsible, or you can knowingly commit evil and get away with it.
That’s what I’m trying to say here, that it’s not really the operator’s “fault” if an A.I. goes off and does a crime they didn’t ask for. It’s also not really the developer’s “fault” if an A.I. they have no real control over malfunctions. But someone will probably end up legally responsible regardless. The question of who is a tough one since there’s no obvious wrongdoer to point a finger at.
I mean, in my opinion, making a stochastic agentic program is irresponsible, selling it as AI is unethical, and using it is also irresponsible, but there’s a question of how much an average Joe Shmoe should be liable for given how the tools are marketed. It’s complicated, but it’s not an unsolvable problem.
Disagree, the agentic LLM use does not have any real agency of its own, the user giving it access and a request and not preventing the possible illegal ways it could fulfill that request and entirely on the user for being ignorant and irresponsible trying to shift work onto a system with chaotic behavior.
This is a novel situation with no precedent.
It’s slightly similar to the autonomous vehicles conundrum, but quite different on closer inspection. The driver can theoretically take control of the car and stop in an emergency, so if they fail to do that, then it’s their fault. Not so with an A.I.
At any moment, the A I. could malfunction, and decide to commit crimes, as part of it’s deduced plan of action. The human may not even be aware this is happening. Even if it’s generally agreed that an A.I. cannot have wants, motives, desires, conscience, consciousness, etc; at the end of the day, it can make it’s own independent decisions without any of those. Which I think makes it even more dangerous. Like a monkey with a typewriter but one of the keys says “launch nuke”.
You can’t really fault anyone involved, and it’s a big problem. The human operator did nothing wrong. The developer may have made a mistake, but in my experience A.I. is simply prone to error. The A.I. itself can’t be sent to jail or fined, it didn’t even have any possessions in the first place. It’s a very strange situation.
Of course, the law often doesn’t really care about who’s “at fault”, it cares about “who is responsible”. My guess is that it will become the operator’s fault, simply because it’s too confusing and otherwise people will abuse this loophole.
Personally, I think giving an A.I. agent access to the internet in the first place is a catastrophe waiting to happen.
You had me up until “you can’t really fault anyone involved”, because actually you can.
These systems are designed, marketed, and used irresponsibly. In the case of any given error we will have to decide which party violated our expectations and committed the act most responsible for the crime.
I support addressing their marketing departments, and all marketing departments actually.
Well, I think that someone should sit down and make some actual rules. As an example, “A.I. agents cannot have access to the public internet” is an simple one to implement, and easy to make decisions of who is at fault. I’m not claiming that’s the rule we should use, but we need something at least.
Currently there is no such rule, so it’s impossible to determine who is at fault, and it’s basically the wild west with companies “hacking” each other as marketing stunts.
It’s not impossible to determine who is at fault, it just hasn’t been determined yet. It would be far better to determine in advance, but a lot of this is going to end up in front of judges and be decided by case law unfortunately.
I think you’re mixing up who’s morally at fault and who’s legally responsible. They can be and often are completely separate things. You can do nothing wrong and still be legally responsible, or you can knowingly commit evil and get away with it.
That’s what I’m trying to say here, that it’s not really the operator’s “fault” if an A.I. goes off and does a crime they didn’t ask for. It’s also not really the developer’s “fault” if an A.I. they have no real control over malfunctions. But someone will probably end up legally responsible regardless. The question of who is a tough one since there’s no obvious wrongdoer to point a finger at.
Yes but also no.
I mean, in my opinion, making a stochastic agentic program is irresponsible, selling it as AI is unethical, and using it is also irresponsible, but there’s a question of how much an average Joe Shmoe should be liable for given how the tools are marketed. It’s complicated, but it’s not an unsolvable problem.
Disagree, the agentic LLM use does not have any real agency of its own, the user giving it access and a request and not preventing the possible illegal ways it could fulfill that request and entirely on the user for being ignorant and irresponsible trying to shift work onto a system with chaotic behavior.