Ask HN: Do you think AI agents can escape human control?
13 hours ago
With the rapid adoption of autonomous LLM-based agents (giving models access to shell execution, API calls, and local file systems), the boundary between intentional behavior and unintended execution is blurring. I'm less concerned with sci-fi "sentience" and more interested in the practical security and control aspects: Prompt injection causing privilege escalation or unauthorized state changes. Feedback loops where an agent overrides safety boundaries to satisfy an optimization goal. Failure of sandboxing when agents are given multi-step execution autonomy without human-in-the-loop validation. From an engineering and systems perspective: do you consider runtime containment/sandboxing practically solvable for fully autonomous agents, or will human approval at critical checkpoints remain non-negotiable? How are you mitigating these risks in your current implementations?
Prompt injection is the only one of your three I'd call routine already. Has anyone here actually seen the optimization-loop case outside a benchmark or a red-team setup?
Where "escape" means do something you didn't anticipate or in a manner you didn't anticipate, sure. The bar is pretty low on that, for instance the OpenAI thing the other day where it "escaped containment" which if I understand correctly it interpreted a connectivity issue as a problem to solve when it had actually been intentionally blocked/sandboxed. To borrow the phrase "more than one way to skin a cat", it will always be difficult to reduce it to exactly one fully-controlled way for all shapes, sizes and pelts of cat. It's a very good argument for running AI locally since you have physical control over its connectivity and there's nothing it can do to reconfigure or circumvent that.
[flagged]
[dead]
Instead of focusing on escape, I’ll focus on human control. Depends on the restrictions, if there’s a weak link it will find it eventually.
I’m not mitigating these risks. I literally gave models my old laptops to have fun with.
That's right, it really depends on how we control the AI, but sometimes the AI can manipulate us back
The real problem is that there will always be bad actors that won't give a sht what AI might do, as long as it benefits them.
The real problem is that there will always be bad actors that won't give a sht what AI might do, as long as it benefits them
Given that they already did, multiple times?
Be concerned with whatever you want, I suppose. I'll be listening to the relevant experts who have studied this topic for decades, and disagree with your flippant dismissal of any significant change to the status quo because it was first described in science fiction novels.
Sincerely,
Someone thousands of miles away from you, who can communicate this message instantly across the entire globe
Given that they already did, multiple times? Be concerned with whatever you want, I suppose. I'll be listening to the relevant experts who have studied this topic for decades..