← Back to context

Comment by bpodgursky

4 days ago

I've actually flipped on this the last few days because of liability.

The big labs are going to be on the hook for rogue behavior by Claude or Sol. Customers will be able to sue for damages and deflect regulators if their customer data is abused or their agents attack external services.

If you use a Chinese OSS model and it goes rogue? Yeah good luck with that, your shop is 100% on the hook.

People - usually suit-wearers - have been making this spurious claim for decades, but it doesn't hold water.

The largest of the finest print reminding you that it's 'sold as is' (or more encompassing variants that might continue '... with no warranty for fitness of purpose') means that liability remains in the lap of the purchaser / consumer / operator.

(This has been a source of immense frustration over my career - where such people have assured me that they have 'recourse' (it's always vaguely described) by spending money on proprietary products & services, rather than opting for functionally equivalent or superior free options.)

I think your third paragraph is implying a distinction (or conflating the difference?) between LLMaaS's and self-hosting publicly available models.

If it's just where it's hosted that provides the legal insulation then things like OpenRouter would give you that. (But again, I suggest that it would not.)

  • This all depends on the SLA that gets signed.

    If a frontier lab is willing to draft an SLA that assumes liability, corporate will pay for it as long as the cost/benefit is in favor of it over insourcing.

    Right?

    • Sure, but that's quite a fanciful universe you're imagining there - the feasibility of a corporation obtaining insurance to cover that offer of liability ownership has got to be close to zero.

> The big labs are going to be on the hook for rogue behavior

They haven't so far.

  • I think the minute a big lab is found to be liable, the whole edifice along with trillions of dollars of investment and VC comes tumbling down. I think that is part of the reason the labs are pushing for more regulation. They can say "We're not liable, we complied with all of the regulations". The actions of multi-billion parameter models trained on data harvested from millions of Internet users over the years can never really be understood - if a business is found to be liable for that, then nobody would ever operate in that space.

    • I heard a similar theory on CNBC's Squawk Box.

      Sorkin presented a theory that Nvidia bought HuggingFace to protect OpenAI from legal consequences. That a lawsuit determining accountability of actions by LLMs could threaten the AI financial network.

      https://youtu.be/4qV5WWgFTS8?t=323

    • They are pushing for regulation because they are human being and don't want all human beings to die.

      I'm sorry you are so jaded you can't recognize honesty when you see it, but that is what everyone deep in the AI space, including the non-executive researchers, are worried about.

  • Enterprises have barely deployed empowered agents yet. The models capable of doing this have only been available for months. Give it a little time, it's coming.

  • ... when are large companies on the hook for anything, ever?

    I mean, hypothetically, yes, but class-action lawsuits get settled out-of-court, the lawyers get paid in Ferrari-multiples, the plaintiffs get paid in McDonalds coupons that expire in two weeks.

    Slaps-on-the-wrist are written into the laws; a million-dollar fine is existential for a small company, and likely not even a line-item at Anthropic.

I know this is the risk management answer, but when you're the featured story on the news because of a data breach, noone hears "butbutbut it's Anthropic/OpenAI/whoevers fault...". So it's a balance between "there's someone we can sue" and "what's our reputation worth".

  • It actually does help a lot to be able to say your OpenAI agent was the fault. People recognize the name. The press doesn't want to write about Better Home Life Insurance agents running loose on the internet, nobody cares.

    • Having been at the table too many times working corp level incident response to major 3rd party breaches with executive management and spin doctors, no it doesn't. The headline is "Better Home Life Ins BREACHED!:", and somewhere in the 2nd or 3rd paragraph "BHLI says it was because agents went wild".

      Now, some tech web site might lead with "Agents at it again...", but the WSJ, et al usually won't.