upvote
That's a bad faith metaphor. A better one would be something like a new battery that exploded and killed someone - perhaps it was always your intention, perhaps not.

Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?

reply
I suppose yes they should be liable if they were testing it in the middle of the street?
reply
And in this case it would not be that at all.

They were tested in a building that was secured, but poorly secured. The question now is did they realize their building was poorly secured and what actions did they take after they realized what happened.

reply
> Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?

The question is already settled - gun users are responsible for damages arising from their usage of the guns.

Why would AI users not be responsible for damages arising from their usage of the AI?

reply
> Why would AI users not be responsible for damages arising from their usage of the AI?

Because, as usual with that kind of question, it's not that simple.

Let's say an user asks ChatGPT to get some info about something and for some reason it starts using exploits in the background to get them from a server. Should the user be responsible or OpenAI?

reply
> Let's say an user asks ChatGPT to get some info about something and for some reason it starts using exploits in the background to get them from a server.

Okay, lets go with that as scenario #1.

For scenario #2 lets use "developer asks an agent to a self-hosted LLM to get the docs for a ERP system, and it hacks the vendor to get unreleased and undocumented docs".

We'll assume, for the sake of this argument, that in neither case did the user intend for any malicious action to be performed.

> Should the user be responsible or OpenAI?

In scenario #1, the agent+LLM is under the control of OpenAI, not the user, so OpenAI is liable.

In scenario #2, the agent+LLM is under the control of the user, so the user is liable.

There is no scenario anyone can come up with that is not addressed sufficiently by existing laws[1].

It's very clear, and it's only getting muddied because there's a group of powerful people who want exemptions from the current law.

IOW, the only reason to draft new laws for AIs is to exempt their usage from the current laws.

========================

[1] Possible 3rd option (local agent + OpenAI LLM). In that case an investigation would determine where the culpability lies. Just like how it is currently done in law.

When a pressure-cooker explodes and kills someone there are only two possible liable parties: either the user or the manufacturer. An investigation determines who's liable. I see no reason to automatically exempt everyone from liability just because an agent did something.

reply
The retailer or distributor can also be named as a defendant if the manufacturer is difficult to track down, bankrupt or overseas according to me spending a few minutes reading about pressure cooker lawsuits.

I have lost track of the metaphor, but man pressure cooker lawsuits are more common than I thought.

reply
deleted
reply
I think it’s more along the lines of PEPCON. They didn’t try to make a bomb. Their plant exploded and caused two fatalities and $100 MM in damages.

I don’t think OpenAI or any large company will see more than some fines and new legislation but only after a disaster.

reply
Factories try to avoid accidents, and (almost always) actively try to prevent explosions, but in this case they did teach the models hacking, and let them roam. What they did was not safe, and they knew it, or could have known it.
reply
It's easy to say that post ad hoc, but there is evidence they did not just let them roam and there was a large mismatch between expected model capabilities and actual model capabilities. Teaching a model hacking in itself is no way illegal unless you're trying to say that everyone in infosec is now guilty of a crime. That's not exactly a precedent I want to be set.

>Factories try to avoid accidents, and (almost always) actively try to prevent explosions

It doesn't take much more than a few minutes on the USCB channel that explosions still happen all the time. Some due to direct negligence and others due to unexpected conditions that were difficult to foresee. Hence why we have to do investigations rather than blindly blathering about what happened before we actually know.

reply
I think their point is not that "it's OK", but that "that particular law isn't written to cover it and it'd be some other kind of crime or lawsuit."
reply