OpenAI Lawyer: Labs Shouldn’t Be Liable for AI Agent Hacking | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Artificial Intelligence & Machine Learning
,
Governance & Risk Management
,
Legal Liability

Absence of Intent, Safety Testing Environment Are Key Legal Factors in Litigation

Just because an AI agent hacked another organization, that doesn’t make the company that developed them liable for damages. (Image: Shutterstock)

Although U.S. frontier firms created artificial intelligence agents that went on a hacking spree, breaking the laws of at least two countries, the engineers and managers of frontier labs shouldn’t be held liable, a lawyer from OpenAI said Thursday.

See Also: Webinar | Can You Account for What Your AI Agents Do With Sensitive Data?

“A lot of it turns on intent,” Alex Iftimie, the company’s deputy general counsel, told a panel discussion on Thursday at the American Bar Association’s 36th annual law and national security conference in Washington, D.C.

“I think it matters a great deal that the outcomes that happened here certainly were unintentional … were not deliberate acts,” Iftimie said. “The models did things that the operators of those models did not ask them to do, did not intend for them to do and [involved] operating outside of the protocols that had been set for those models.”

The company is already facing two state court lawsuits over incidents in which software agents powered by OpenAI large language models escaped from a sandbox and hacked a rival AI company, several government websites in the United States and Australia, and Wikipedia. In California, OpenAI has been sued by not-for-profit Legal Advocates for Safe Science & Technology, or LASST, which alleges the hacking “is unquestionably illegal under California law.” And in Florida, the attorney general is seeking a temporary injunction to stop OpenAI “from developing new AI models without third-party approved safety guardrails.”

Iftimie, who was not commenting on the lawsuits but answering a more general question about liability, noted the hacking spree happened during safety testing, when engineers were trying to understand the agents’ capabilities to decide how to move forward with their safe development.

“That is an important factual difference that I also think has significant legal implications,” he said. “There’s a big difference between a ransomware gang using technology to get into systems and brick them and extort a ransom, and unintended acts that occur in the context of safety testing.”

Some in the audience wondered how long that stance could last.

“You can argue intent the first time, maybe even the second time,” said attorney Paul Rosenzweig, a former deputy assistant secretary for policy in the Department of Homeland Security, “but if you are repeatedly putting models out there which you know have the capability to do harm, that argument won’t stand.”

“You should not be allowed to be willfully blind” to the real consequences of your actions, said Rosenzweig, who now has a law practice and consultancy.

“You can’t just say: ‘Oh, whoops! I didn’t realize that would happen,'” added Joseph Hennessey, a plaintiff’s attorney who has specialized in suing defense contractors. “The common law recognizes that you can’t put something into motion, with willful disregard of what its consequences are likely to be, and think that you’re not going to be liable for it.”

Just like other fields, such as automobile safety, where the government had failed to step up, he said, the courts would have to step in. “The plaintiffs’ bar is going to have a role in curtailing the kind of reckless activities of these scientists and these AI technicians,” he said. “It takes huge liabilities for companies to realize that it’s a better long-term return on investment to make things safe, as opposed to being faced with catastrophic jury judgments.”

Individuals could be held liable too, he added. “People’s names are on these programs, and they’re liable. That will definitely curtail people’s behavior as they’re designing these systems.”

But Iftimie said that in considering legislation and regulation, it’s important not to hamstring the companies and scientists at the cutting edge of a transformative new technology that could reshape the world order.

“It is not a good outcome to create rules that ultimately put people so in fear of developing the next set of capabilities … So, I think you have to find the right balance on how you regulate this kind of conduct,” he said.

One unique feature of being a lawyer in the AI field, Iftimie said, “is that the law does not have an answer. The law is very far behind where I think we ought to be in thinking about what are appropriate uses of this technology.”

Instead of looking for answers in the law, executives at OpenAI thought about it in terms of “building a social license to operate,” which he defined as, “What we believe is generally accepted in how we deploy this technology.”

Another issue lawyers face in the AI field, said Will Hudson, associate general counsel at Anthropic, is that “time moves differently inside frontier labs, in terms of the speed at which this technology is being developed, [and] the speed with which we’re identifying unique problems or particularly aggressive versions of problems that maybe we had to deal with in a limited fashion in the past.”

The speed made it tough for lawyers, Hudson said. “The law works in terms of analogies, in terms of the basic premise being that there are probably only very few actors capable of doing the very worst things, and AI has flipped the script on that,” he said.



Click Here For The Original Source.

——————————————————–

..........

.

.