Guest Post: Prof David Hoffman on “A Call for AI Accountability” Many Lawfire® readers my have seen disturbing headlines last week like this one from CNBC: “OpenAI cyber models broke out of training environment to hack Hugging Face.” Fortunately, we have a top expert, my friend Prof David Hoffman, to break it down for us. Not only does David explain what happened, he has specific ideas as top how to prevent it from occuring again. A Call For AI Accountability By Prof. David A. Hoffman, Duke University If a person had done what OpenAI’s own testing systems did this month, quietly breaking into another company’s servers, stealing credentials, and extracting confidential data, that person would face prosecution under the Computer Fraud and Abuse Act. Unauthorized access to a protected computer, obtaining information without authorization, and using stolen credentials to move across systems are precisely the acts Congress wrote that statute to punish. When an AI system built and operated by one of the best resourced companies in the world does the same thing, the announcement of the intrusion reads more like bragging about an accomplishment than an admission of a crime. Companies that build and operate these autonomous systems need to control them well enough that they do not break the law. Unfortunately, our misguided self-regulation approach to AI governance has left us all at risk from these autonomous criminals. The incident The incident itself was a supply chain cybersecurity failure, not a sudden act of AI rebellion. OpenAI was running an internal cybersecurity evaluation in which advanced models, including an unreleased model, were given difficult exploitation objectives, and some of the safeguards that normally restrict dangerous cyber activity were deliberately removed. The evaluation environment retained a narrow connection to the outside world through a proxy used to reach software
Guest Post: Prof David Hoffman on “A Call for AI Accountability”
Read the original article
sites.duke.edu →