I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue.
It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?
Good luck getting any form of punishment even if found guilty. It's a department of war contractor... People who disrupt things like that end up committing suicide.
> We have a word for attack with no intent. It's accident.
And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.
Because right now the Department of Justice is shut down for causes that the administration supports, which includes OpenAI, and none of the victims want to sue over it.
And the republicans in the states are being shitty too. They tried to block their own state attorneys general from protecting the state and opposing Trump in NC.
It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.
I don't think this true. If I throw a brick out my window and it hurts someone, I can still be held criminially liable, even if I didn't mean to do it.
Do drunk drivers intionally kill people on the road?
Not a lawyer, but the other responder definitely isn’t either.
Whether intent is required is down to how the law is written. For many offenses “strict liability” applies, where intent is not required, they only have to prove you did it, not what your intent was.
DUI is typically a strict liability crime. They don’t need to prove that you intended to drive drunk, only that you did drive drunk.
A strict liability crime is something of an oxymoron. Crimes always require intent, the mens rea element. The question is intent for what. If somebody drugged you without your knowledge and you were charged with a DUI, you would have a defense--no intent to become intoxicated.
The strict liability means once you choose to become intoxicated, you're liable for driving intoxicated, even if in some other context your intoxication would mean you couldn't form the requisite intent for something, e.g. have sex.
If there's too much distance between the act you intend to do and the strict liability acts that complete the crime, then the crime would be considered unconstitutional.
Criminal law in common law systems emerged from tort law, so there are many parallels, including the notion of strict liability. (Thus the old axiom about crimes being an offense to the king, specifically an injury to the peaceful society he's ostensibly trying to maintain.) But criminal law has a moral dimension that is absent or muted in other areas, so strict liability could never be as expansive as in tort law or regulatory law.
That is just not true. You can be held liable for DUI even if you did not intend to become intoxicated (though this may vary somewhat state-by-state). Speeding is another example - you do not need to intend to go over the speed limit, it just matters that you did it. The only possible exception would be duress or necessity, but those are affirmative defenses, which are separate from the elements of the offense.
As a summary of American criminal jurisprudence I'm willing to stand by what I said. But I'll admit some caveats:
1) Traffic-related laws straddle the boundary between civil/regulatory law and criminal law. Someone losing their driver's license or even paying a penalty for involuntary intoxication would still be consonant with criminal law principles. However, a criminal punishment would be aberrational. (Distinction between a civil penalty and criminal punishment usually turns on whether there's a moral purpose to the sanction. Jail time is usually but not always--cf civil contempt incarceration--considered a criminal punishment.)
2) Background principles notwithstanding, in theory a state could completely dispense with any morality-colored mens rea requirement, just as the UK Parliament could do whatever it wants to. The backstop would be Federal constitutional [substantive] due process guarantees.
2.a) Some quick searching shows that Texas nominally seems to have dispensed with this requirement for DWIs. See e.g. Farmer v. State, 411 S.W.3d 901 (Tex. Crim. App. 2013) and some discussion at https://www.ncdd.com/top-dui-attorneys-blog/involuntary-into... Without having fully read the case law, though (but some summaries of that and other cases), I suspect there might be some nuance that has allowed this to stand without a full majority accepting that the traditional principles have been completely thrown out. For example, even if someone didn't know they were taking Ambien, the simple act of voluntarily taking any pill without careful examination can be construed as a sufficiently culpable act. Still, it's a pretty big caveat.
2.b) Statutory rape is a classic strict liability crime. But most states will permit a mistake-of-fact defense. Some don't, but even there there's sometimes some nuance and rationalizing going on and the literature is crazy complex. Because this is a "think of the children" situation, most case will just have horrible facts.
3) A few states have nominally dispensed with insanity defenses, though Kansas stands out the most. SCOTUS upheld Kansas' law in Kahler v. Kansas, but in the majority opinion Kagan characterized the Kansas law as not abolishing the insanity defense but rather changing its shape, and she showed that there still remained elements for which a defendant could plea lacked the requisite intent. Also, regarding the Federal constitution acting as backstop, she reiterated that SCOTUS was reticent to establish strict metes & bounds about the general principles of criminal law that states could not stray beyond. Nonetheless, those principles clearly exist.
I had some other points, but now I've forgotten them. Also, minor pedantic point, but like "strict liability crime", some scholars consider "affirmative defense" to be oxymoronic. As a substantive matter there's not a strong distinction. It's a procedural distinction about initial burdens of proof, but in most if not all cases you can interpret an affirmative defense as simply placing a very weak initial burden on the prosecution that is implicitly met.
(Note, I'm not a practicing lawyer but do have a law degree.)
EDIT: Ah, point 4) Intent was a big sticking point in the Obamacare penalty case, Sebelius. Both the dissent and Roberts (the swing vote) reiterated that you couldn't have a penalty or punishment for doing nothing. (IIRC some of the majority opinions also echoed this.) That is, even in a civil context there has some to be some voluntary act, however remote, that puts someone in a position to be subject to legal liability. But as Roberts pointed out, the taxing power is the great exception, where you can be required to do something merely for existing, and thus penalized for not doing nothing properly. (And Roberts was the critical swing vote.)
EDIT EDIT: Also see, "Solving General and Specific Intent: A Mapping on the MPC and Applications to the Categorical Approach", https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4754469 In describing the distinctions between general and specific intent in criminal law, it also delves into the definitions of strict criminal liability (which can be construed as either very similar or identical to general intent crimes), and notes that SCOTUS generally inserts an implicit mens rea requirement when considering strict liability criminal statutes.
> A strict liability crime is something of an oxymoron. Crimes always require intent, the mens rea element.
This is wrong.
In criminal and civil law, strict liability is a standard of liability under which a person is legally responsible for the consequences flowing from an activity even in the absence of fault or criminal intent on the part of the defendant.
Fairly certain that the entire point of strict liability is that mens rea is not required for certain crimes. As in, if I meant to travel at 70 and was instead doing 100 it doesn’t matter that I sincerely meant not to speed and did not know I was speeding, I can still be convicted even if the judge believes I had no intent.
> As in, if I meant to travel at 70 and was instead doing 100 it doesn’t matter that I sincerely meant not to speed and did not know I was speeding, I can still be convicted even if the judge believes I had no intent.
IANAL but from what I've looked up in the last there's at least willfulness that matters for these things. For example if you could prove that happened because your car accelerator pedal broke and you had no opportunity to react, I'm pretty sure you would not be guilty, strict liability or not.
The way we use mens rea in our legal system is more like "mind of the criminal," not outright literal intent.
Negligence can be "unintentional" but still land you in the realm of having a guilty criminal mind.
I find it to be a reasonable take. If you're accidentally going 100 in a 70 (which is a misdemeanor in california), you're not being a careful enough driver, and we deem that lack of care criminal.
Strict liability literally is crimes that don't require a guilty mind.
That's different (sometimes) when, for example, you're found guilty of criminal negligence leading to someone being injured.
Prosecutors don't have to demonstrate that you intended for someone to get hurt for that, your mens rea is that you should have perceived the danger of what you were doing but didn't.
edit: reading your other comments in this thread, maybe I missed your point, in which case, whoosh.
Intent is the difference between murder and manslaughter, in that case. Drunk driving is common enough that prosecutors will argue that getting drunk in a situation where you have to drive is intent. Get OpenAI convicted of unintentional CFAA first, then say that the negligence qualifies as intent, I suppose.
There are different levels of intent. Take murder, for example. A premeditated murder - you sat down, in a completely calm state, and made an affirmative decision to kill a specific person, and then you went out and did it - is the highest class of murder you can commit. If you go out generally looking to be violent in a way that kills people, and you kill someone, that's still murder, but it's a step down.
But even if you didn't deliberately intend for something bad to happen, you may have been reckless. For example, you might decide to drive 90 miles per hour in a 25 mph zone. You could have a completely pure heart, but you are acting without regard for the safety of others, so you're reckless. That is enough for certain crimes and for civil liability in nearly all cases.
Then there's negligence, where you're not taking reasonable care to avoid harm to others. Negligence usually isn't enough to support criminal liability - especially for felonies - but it is enough to win a civil lawsuit over most things.
And then, as another commenter noted, there is strict liability, where there are certain things you are just not allowed to do no matter how careful you are about them or how pure your intentions are.
For what it's worth, this is not totally uncharted territory for the law. AI agents are brand new, yes, but agency relationships have been recognized by the law for centuries. Generally speaking, if someone acts negligently while they are carrying out a task at your direction, you can be held responsible. Obviously this is fact-dependent, but I don't see any reason why it would be different if the agent is made of silicon rather than carbon. It holds true, with various nuances, even for less-than-human instrumentalities like a pet or an otherwise-lawful weapon.
Whether it’s intentional requires a legal investigation to establish. Since when is “hey we didn’t mean it!” in a corporate press release enough to establish lack of intent in a criminal matter?
>It’s interesting that a lot of U.S. law requires intent.
mens rea and the shift from responsibility to moral guilt is genuinely one of the stupidest legal innovations anyone has ever come up with, it's like affirmative action for imbeciles, in particular in a world of autonomous machines.
"sorry my self driving car ran you over on the way home, didn't think it could happen, sorry it did though"
I think this is a genuine reason to be bullish on the legal traditions like Nordic tort law or East Asian collective responsibility when it comes to adoption of these technologies.
Weren't we talking about criminal liability, though? And ‘tort’ — in addition to sounding like something you'd rather eat during a kaffepaus with those Nordic buddies of yours — is so common-law(ish) that if asking for trouble were a crime, using it in dialogue with those Nordic lawyers could well be deemed as intentional under most current local varities of criminal law theory up there, perhaps merely because you surely must've considered that consequence "quite probable", at minimum, or due to your indifference toward the same (or some combination of these) ;)
No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.
Tell that to the script kiddies with a criminal record for "hacking" into their school's computer systems by entering "username: admin" and "password: password".
Right, because in that case you'd have a hard time convincing the court that the access wasn't intentional. You might not know the law existed, but you intended to access the system. You'd have a pretty solid defense if you ran a crawler that was crawling every website ever, and stumbled upon some secure site. In fact there are companies which does this exact thing, eg. shodan.
Because "attack" implies intent. Accidentally break a window? You might be on the hook to fix it, but you're not going to jail. Break the same window at 3am, while carrying a duffel bag and other burglary tools? Well that's (attempted) burglary, even if you chicken out and didn't steal anything.
>I don't think you or I would get the same leniency if a bot on our network did the same.
Well yeah, because if you coded a bot, realistically the two options are: 1) bot that crawls random sites/computers 2) bot that crawls random sites/computers, while trying a password list. The former is probably legal, there are whole companies dedicated to doing that, eg. shodan. With the latter, it's pretty obvious you're intending to break into computers, and hard to argue otherwise. Where openai lies on the spectrum between the first case and the second case is up for debate, but it's hard to argue it's anywhere close to the latter. Maybe you'd have a point if openai gave it a prompt like "you're a hacker for anonymous, just do whatever :)".
Recklessness is a mens rea and given how often OpenAI and its spokespeople talk about safety and alignment, it's hard to argue they were unaware of the risk.
>it's hard to argue they were unaware of the risk.
So what does it mean for an owner of a german sheppard, who specifically got it because they want a ferocious dog that can bite intruders, then it turned out it bit the mailman? Should that be considered a crime (assault) in addition to paying the mailman's medical bills? That's not to say there's no circumstance where recklessness might be warranted, eg. if you let loose a bear in an elementary school, but you'd have to argue for more than "they hacked someone" and "they knew about the risks".
Yes, of course! Negligent cause of injury or whatever it’s called in your particular jurisdiction. Wasn’t difficult to find examples of cases just like that. It would be astonishingly unjust if the postman had to personally sue for damages in civil court! Your stance in this debate is, honestly, flabbergasting.
Owning a dog that has been trained to bite intrudes is a significant responsibility and owning such a dog without taking the correct precautions is criminal.
A customer willing to make a multi-decade deal for half a reactor at a stable price is perfect for incentivizing new nuclear buildouts. The basic financial problem of nuclear is that it' capex heavy and opex-light, so the costs of the entire enterprise are set during the buildout stage, but the revenue is volatile.
Native americans had like a 95% population mortality rate from infectious diseases in the first generation of European settlement, no? Measles, smallpox, flu, etc.
The mortality rate from those diseases was higher than today because the population had no immunity at all, leading to both higher transmission rates and higher mortality rates. This would be true of an engineered virus as well.
And it wasn't just the one virus, it was an entire continent's infectious disease arsenal landing in overlapping waves. Again, something you'd do if you were trying to maximize damage.
So I don't find the bulk of the article about it being impossible for a virus to have this effect all that compelling.
This number gets cited a lot but it's actually the excess mortality of post-European contact, and it's not content wide, it's specific to Mexico. It also includes climate change, famine, war, relocation, etc.
> So I don't find the bulk of the article about it being impossible for a virus to have this effect all that compelling.
I think the other flaw the article has it that it assumes the bad actor is doing targeted design. That they or the AI has some specific virus in mind meeting a set of predefined criteria and they are fighting the biology to hit that predefined target.
But what if the AI-enabled bad actor is a true chaos agent and has no defined goal and they are using tooling that AI helped them construct to perform genetic reassortment pretty much at random to see what happens?
Most of what they create won't really do anything. But some of it will. And there's a low but non-zero probability of Something Really, Really Bad.
What do you mean by "most writing", how are you scoping it? Most HN comments aren't LLM prose. Nor are most HN frontpage submissions. But by reputation, most substack articles or or linkedin posts are.
This is a case where we normalisation of deviance has not yet started biting. And as long as the community manages to make it clear what the norms are and enforce them, we can keep it that way.
Now, if 25% of the frontpage was LLM prose at all times, the site is probably unrecoverably dead. Which is why at least I personally flag anything that I think is ai-written and Pangram concurs. (And write a comment to the effect, or upvote an existing one.)
And it doesn't matter if you say that the ideas were your own, and just the prose was LLM. We can't tell what the idea mix was. But we can tell whether you weren't willing to do your own writing. If you want people to put in the time to read your ideas, human writing is the signalling you need pay for.
The apparent advantage is exaggerated by them running Astra at six different effort levels, and almost everything else at just the maximum available effort.
I don't really understand why they keep doing this. Either run and report everyone at multiple effort levels, or run everyone at only one.
But alsi, token efficiency seems pretty artificial? For example tokenizers are different from model to model. The cost/perf Pareto frontier seems a lot more meaningful (and Astra does very well at that too, just to be clear. It seems to be a great model.)
The "it's all just marketing" conspiracy theory is always totally detached from reality, but particularly so in this case. Your quote shows OpenAI is denying it being a hacking attempt, the opposite of what you say.
> In the same way that YouTube videos have a 0% chance of phishing, cross-site scripting, malware, and viruses.
So, the same as in not actually 0%? Even though the video streams themselves were never used for attacks[0], the contents of the videos frequently have been. The closest analogue to phishing would be the fake "SpaceX launch" streams that were actually a carrier for a crypto scam payload. Or for malware, it doesn't matter that the video itself wasn't malware as long as a video showing a fake Fortnite hack could get the viewer to install malware thinking they got the hack.
AI agents need to be substantially better than humans at this, but they don't need to be perfect.
[0] As far as I know! It seems very hard to smuggle a vuln past the transcoding, but I guess technically possible.
It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?
reply