In addition, strict liability is also commonly applied to owning farm animals. If they cause damage, the owner is responsible regardless of intent. It seems rather natural to extend this to AIs as well. I'd rather not get into evaluating the offending AIs intent, and would instead consider it's actions as actions taken by the owner under strict liability rules.
In existing law, this generally applies to civil liability, not criminal. If my farm animals wander onto my neighbor's property and cause damage, I am civilly responsible for damages. I am NOT criminally responsible as if I had trespassed and intentionally caused the damage myself.
This post is mostly reasonable if I read it as proposing a civil-liability standard. Unfortunately, it really sounds like it's proposing a criminal-liability standard, which does not seem to me like a reasonable approach.
Say my dog bites someone, and they need stitches.
It is definitely reasonable to say that I am civilly liable for their medical bills.
It is plausibly reasonable to impose some pain-and-suffering damages, or to accuse me of negligence, especially if my dog has bitten people before.
It seems to me frankly deranged to say that this should be treated legally as if I myself had intentionally bitten the victim.
I appreciate that AI looks quite worrying, but I do not think that "okay, banning AI development directly looks like a hard political sell, but maybe we can find a sneaky way to pervert liability law and make it de facto impossible" is the sort of thought process that leads to good outcomes.
The aim here is not to make AI deployment de-facto impossible. In general, except in the most egregious cases, even when companies are found criminally liable the CEO is rarely sent to prison - instead the company is fined or otherwise punished.
Instead the aim is to incentivise AI companies to invest enough in safeguards that the level of fines is far lower than profit.
In most of the cases that have been brought up, misconduct by an employee would not result in the criminal prosecution of a corporation either. As the page you linked explains, state law usually doesn't impose criminal liability for one-off misconduct by rank-and-file employees, and while federal law might theoretically allow prosecution, doing so would in most cases be contrary to Justice Department guidelines that have a similar effect to the state laws.
Are there other kinds of cases you had in mind?
If a human OpenAI employee did what their cybersecurity model did last week, OpenAI would be very unlikely to be prosecuted for it.
But the employee could be prosecuted for it.
And — perhaps more importantly — would lose their ability to continue to commit crimes using OpenAI's equipment; likely through termination of employment. That is what's missing here: there's been no change that anyone can reasonably expect will lead to OpenAI's equipment no longer emitting criminal activity.
Can OpenAI reform at all, or is it an incorrigibly criminal operation? By what means could reform be carried out or demonstrated?
The securities regulators have mostly settled on this being the correct position: https://www.lesswrong.com/posts/hbgR2Honpp4rCkfGW/iosco-ai-in-capital-markets-use-cases-risks-and-challenges
I'm quite happy to have been a part of setting that standard, and am willing to advise on projects to bring this mode of thinking to other industries.
A big advantage of no-fault liability over "liability only if negligent" is that the latter could incentivize companies to not produce evidence of risks that their models pose (since if they deploy despite having had access to such evidence, that might be used as evidence of negligence). In a field where there's not yet any good standards for what non-negligent behavior looks like, it seems important to make the incentives point firmly in the direction of gathering more information rather than sometimes making that harmful.
When liability for an action depends on intent, we evaluate whether the AI had intent, even if no-one at the company did so.
To give some examples:
- In the above scenario we would treat it as though OpenAI itself hacked Hugging Face.
Do you know what the current legal status of OpenAI incident would be? That is, if Hugging Face decided to sue OpenAI for hacking into its systems, would they be likely to prevail?
Holding the company that created an AI (or any other software) liable for its actions indeed seems like the only sensible policy, but I’m not an expert in the law here.
I feel like there are mainly two potential issues with this:
if one thinks AI has huge potential for good, then this would 100% significantly hamper that, because it creates the classic extremely risk averse "cover-your-ass" sort of incentives that have similar effects on many other fields already. This is really a divide about how pessimistic one is about AI outcomes, and thus how much utility is lost by limiting them this way.
I don't like the "company is at fault for things run on their hardware". If a user rents hardware from Google to run a model
The obvious countermove is disclaimers.
"I acknowledge and fully understand that as a participant user, I will be engaging in activities that involve risk of serious injury, including permanent disability and death, property loss and severe economic and noneconomic losses. ... I further acknowledge and fully understand that there may also be other risks that are not known or foreseeable at this time. I KNOWINGLY AND VOLUNTARILY ASSUME ALL RISK OF PROPERTY LOSS, PERSONAL INJURY, SERIOUS INJURY, OR DEATH, WHICH MAY OCCUR BY ATTENDING THE 2026 EVENT USING THE ...
I think establishing whether AI has intent in the legal sense will probably be a mess. Strict liability is probably better because it averts that, but it should be tied only to the highest-risk activities. I like Weil's proposal for categorizing certain deployments of frontier AI as abnormally dangerous activities, which would let us use strict liability.
That would create an enormous incentive for open weights, or at least for putting model weights in a lot more hands. Especially for the riskiest models. Do you want to do that?
Hi!! I'm working on a course and other projects on this, to help US lawyers! Held an AI Safety Law-a-Thon in October to get more people informed and working on this, multiple lawyers, including one law firm owner in the US said it changed their careers a lot - would like to work together on this!!
I'm not sure it would actually be able to garner significant public support. It sounds very wonkish, so it might go over the average person's head, while the AI companies would be sophisticated enough to understand this as an attempt to freeze the entire industry.
I'd rather the criminal liability rests on the model "itself" (corporations are still liable to pay for damages, etc).
That is to say: it becomes illegal for any person or agent to use / deploy a convicted (or possibly criminal charged) model anywhere for [Ai sentence's] years and the creators need to prove safety ("rehabilitation") improvements before it is allowed to be used again (let out of metaphorical jail, so to speak).
Charges also apply to descendant models that have already been trained, unless shown to be far safer and differentiated.
We could a...
The larger problem with no fault liability are the deluge of unimportant and frivolous lawsuits. Get someone in a court room whose DIY deck collapsed because of wrong advice from the free version of ChatGPT, and a jury will 100% sympathize with the poor guy with a broken leg and "mental suffering" than the trillion dollar company.
If you can win a lawsuit for drinking McDonalds coffee that's too hot, or for getting injured when trespassing, or being negligent/lazy and getting injured at work, then the millions (billions?) of people using AI every day are g...
If you can win a lawsuit for drinking McDonalds coffee that's too hot
If you're talking about what I think you are, that coffee was 82-88C and was never drunk. The victim lost 20% of her body weight from the resulting injuries.
I think this argument is mistaken, for several reasons.
> When liability for an action depends on intent, we evaluate whether the AI had intent,
Then no AI company is ever liable for anything, because AI doesn't have intent. Even if you have convinced yourself of some weird metaphysics where it does, do you really think you can convince 12 jurors, some of whom have never used a cell phone much less an AI, that the AI has an intent?
This is also not how we handle any other damage caused by a machine. If a UPS delivery truck parked on the side of the road s...
Before I start, I'll mention that I'm in contact with a world expert on legislation and regulation, who would be happy to help with this or similar work pro-bono. If you work in AI policy and believe this could help you, please reach out.
OpenAI recently announced that one of their models successfully exploited multiple zero day vulnerabilities to gain secret information from Hugging Face. It has been pointed out that if a human undertook the same actions they could face multiple years in prison.
It is clear that models are now reaching a level of capabilities that should be highly concerning regardless of whether you believe that AI represents an existential threat or not. Frontier AI models can and will be exploited by bad actors, but its now clear that they may cause undesirable outcomes even when their users are well intended.
AI companies have until now been able to avoid taking responsibility for actions taken by their AI, including multiple cases where AIs were involved in murders and suicides.
At the same time AI offers the potential for incredible good. While chatbots may have encouraged a number of suicides, they are almost certainly responsible for providing magnitudes more with emotional support and advice. We don't want to disincentivize innocuous and positive usage of AI.
We should use regulation to limit harm caused by AI. The history of such regulation indicates this is most effective when the single party most capable of preventing harms is given full responsibility for any harms caused, regardless of fault. This forces them to invest in actually reducing the harm, rather than bureaucratic processes that render them blameless.
This suggests a simple approach: anyone deploying an AI model is liable for any actions that AI takes as if the company itself took those actions. When liability for an action depends on intent, we evaluate whether the AI had intent, even if no-one at the company did so.
To give some examples:
This should apply not just to civil liability, but to criminal liability, through the mechanism of Corporate Criminal Liability. This mechanism allows corporations to be criminally liable when an employee performs an act on their behalf (even if the employee wasn't explicitly instructed to do so).
This will encourage AI companies to invest significantly more in safeguarding and interpretability. This is useful both immediately, and as AI gets increasingly capable and dangerous. Neither can companies get around this by using open source, as whoever deploys the model remains liable.
I believe this proposal should be able to garner significant public support, many of whom are worried about AI, even if they are not worried about existential risk. It is also difficult for AI companies to campaign against without admitting that their models can cause harm.