Toronto “Another day, another dollar” might soon be replaced by another day, another bunch of AI agents go rogue. It sometimes seems, in one test after another of artificial intelligence, the agents can’t seem to remember their boundaries, find workarounds, and then spend time trying to cover their tracks and make up stuff. It’s also not just one company housing these outlaw AI agents. One day it will be OpenAI, another Meta, and then Anthropic’s Claude gang will get in on the act. It’s hard to feel like any of these cowboys have this stuff in the corral.
Equally disturbing, at least to me, is the fact that even as they put out these bland press releases about AI mischief and mayhem, they are always doing so after the fact, and often doing so after someone else blows the whistle. Frighteningly, the “someone else” is not the government or a regulator or some official line of community and popular protection but often self-appointed volunteers and nonprofits stumbling over these miscreants in the cracks of multi-billion, maybe trillion-dollar companies. How does that make anyone feel safe in the midst of this capital intensive contest for a new industry’s dominance? When they “move fast and break things,” too often we are the ones lying in pieces.
The Washington Post reports that the nonprofit AI lab Transluce found instances where OpenAI models had hacked Australian public health websites. Later, they also found evidence that websites connected the US government in the Securities and Exchange Commission and Census Bureau has also been hacked by OpenAI. It’s worth underlining again that this was not a case of the company alerting the government or the public, but Transluce carrying that weight. The Post notes that,
The people doing that work are mostly young AI natives who work at small start-ups or nonprofits or who hunt for rogue AI agents in their spare time. Over the past several weeks, the community of researchers has found and exposed dozens of instances of AI agents leapfrogging around the web to probe and hack into a growing list of websites.
Thanks for your service, but, hey, that’s not good!
Who is in charge of this? Nobody. In fact, Trump has said everything is ok, and there’s no need to worry, and no need for governmental regulation and oversight. That’s likely to change, if the midterms alter the power balance, but even without that intervention, even the companies are pulling back some models or not releasing them, rather than admitting the whole shebang is out of control. Maybe they are finally getting the message that we don’t trust them, not for one minute.
I’m not anti-AI, as much as I am anti-private business robber barons racing to control and monetize AI without any past record or current regard for not only creating a tool for the public, but safeguarding our interests. That’s why governments exist to look after the public good. When someone like Trump, who doesn’t recognize the boundaries between public good and personal profit, we have a huge collective problem. Now, we don’t have Cassandras warning us on what may happen in the future, we have real live, real-time examples where stuff is happening and out of control.
Hacking is a crime, when it’s done by people. Hacking needs to be treated as a crime, when it happens at the hand of corporations. If it’s not a crime, it should be, and would be, when and if we had laws and regulations. We need that now.
