Comment by watwut

4 days ago

OP is exactly correct. The fault, agency and responsibility is on management and employees of OpenAI and Antropic for those hacks.

Full stop.

And issue will disappear the moment there will be accountability and investigations.

I take you haven't read the report. The agents found and exploited two zero-days.

I don't doubt that AI companies should be accountable for crimes committed by their agents, but to describe the security containment as a joke dangerously understates the autonomy and danger of AIs.

  • How long did it take these companies to even notice? Why wasn't exploiting bugs in the agent sandboxes anticipated?

    Human failures all around, though it's easier to just blame the models.

    • > Why wasn't exploiting bugs in the agent sandboxes anticipated?

      Let me rephrase:

      "Why wasn't exploiting zero-day vulnerabilities in the agent sandboxes anticipated?"

      This is one the most... interesting comments I've ever read on HN.

      2 replies →

    • Because for the last however many years before these models they were simply incapable of doing so.

      It's like if your rather nice dog suddenly decides eating faces is totally acceptable out of the blue.

      1 reply →

  • Defense in depth is a thing. There should be audit requirements to show that you have done your due diligence in ensuring that the training environment is locked down.

You're conflating legal/moral responsibility with the question of what language is appropriate to use.

  • Are you proposing separating responsibility from the language used to talk about responsibility? That's novel.

    • It's not novel at all, we do it all the time. It's very common to say "program X did Y" without making the conversation about blame or responsibility. But when the program is an AI agent suddenly using it as a subject of a sentence and saying that "agents did X" becomes a sensitive topic for some people.

      2 replies →