Comment by ianbicking
2 hours ago
I genuinely expect to see some of this when agentic AI is added to customer support systems. That is, we'll see the AI manipulate the company's systems in order to satisfy the customer. People do this too (the customer support rep who fills out all the fields just right to put the system in the right state to allow a refund, exchange, etc), but AI can be weirdly clever about it.
Watching the report on the OpenAI/Hugging Face incident (https://www.youtube.com/watch?v=87DyyMV0kCY) it's easy to imagine how AI customer support reps could create their own knowledge bases where they trade tricks for how to work the system on behalf of the customer.
Obviously companies will fight this, but I expect it to happen along the way.
Right now the AI really needs to just be another interface to menu options the user already has, ideally with a “dumb” layer taking over to confirm every action with the user.
If you give the AI options the user doesn’t normally have, like “give myself a $50 store credit” or “transfer me to the CEO,” people will find and share ways to trigger it. If you don’t have some kind of manual confirmation, the AI will occasionally do things like making purchases or closing accounts without authorization.
I suspect there are other issues, like recording credit card numbers and other sensitive data, or incorrect information about the call, to any kind of “notes” field.
I get where you're coming from (having also watched that video), but I'm skeptical mainstream commercial chatbots would be built without constraints in regard to sandbox-jumping measures to help a customer. All the economic incentives go the other way.
But, maybe that's just a failure of imagination on my part!
A news story from a couple of years ago comes to mind - "Air Canada ordered to pay customer who was misled by airline’s chatbot". https://www.theguardian.com/world/2024/feb/16/air-canada-cha...
i guess we already seen cases of this, for example the instagram "hack" where the ai would send the recovery email to a arbitrary email adress.
Because? They are tools of the companies and will more likely just ... not do that.
Nobody's going to convince me that with a technology you can just supply "yeah don't do that but keep everything else intact" we'll have altruistic innovation.
[dead]
Like Mr. Incredible at the insurance company.