In addition, strict liability is also commonly applied to owning farm animals. If they cause damage, the owner is responsible regardless of intent. It seems rather natural to extend this to AIs as well. I'd rather not get into evaluating the offending AIs intent, and would instead consider it's actions as actions taken by the owner under strict liability rules.
In existing law, this generally applies to civil liability, not criminal. If my farm animals wander onto my neighbor's property and cause damage, I am civilly responsible for damages. I am NOT criminally responsible as if I had trespassed and intentionally caused the damage myself.
This post is mostly reasonable if I read it as proposing a civil-liability standard. Unfortunately, it really sounds like it's proposing a criminal-liability standard, which does not seem to me like a reasonable approach.
I am indeed focused on criminal liability. Why doesn't that seem to you as not a reasonable approach?
Say my dog bites someone, and they need stitches.
It is definitely reasonable to say that I am civilly liable for their medical bills.
It is plausibly reasonable to impose some pain-and-suffering damages, or to accuse me of negligence, especially if my dog has bitten people before.
It seems to me frankly deranged to say that this should be treated legally as if I myself had intentionally bitten the victim.
I appreciate that AI looks quite worrying, but I do not think that "okay, banning AI development directly looks like a hard political sell, but maybe we can find a sneaky way to pervert liability law and make it de facto impossible" is the sort of thought process that leads to good outcomes.
The aim here is not to make AI deployment de-facto impossible. In general, except in the most egregious cases, even when companies are found criminally liable the CEO is rarely sent to prison - instead the company is fined or otherwise punished.
Instead the aim is to incentivise AI companies to invest enough in safeguards that the level of fines is far lower than profit.
The reason I bought up intent is because cyber security laws do actually depend on intent. We don't prosecute somebody who accidentally triggers a remote execution exploit, but we do to somebody who did it on purpose.
We don't want to rewrite the legal code for AI, so need to work out how to apply existing law to it.
Triggering a remote exection vulnerability accidentally is exceedingly unlikely to cause any serious damage anyway; that'll just crash the process. Proper exploits do not happen accidentally. If the software has a bug that makes an accidental action cause damage then liability is (or at least should be) on whoever hosts or distributes that program.
In some other cases the intent might actually matter. It'll require major rewriting of legal code anyway, if you want the intent of an AI to be something that can be considered here.
The obvious countermove is disclaimers.
"I acknowledge and fully understand that as a participant user, I will be engaging in activities that involve risk of serious injury, including permanent disability and death, property loss and severe economic and noneconomic losses. ... I further acknowledge and fully understand that there may also be other risks that are not known or foreseeable at this time. I KNOWINGLY AND VOLUNTARILY ASSUME ALL RISK OF PROPERTY LOSS, PERSONAL INJURY, SERIOUS INJURY, OR DEATH, WHICH MAY OCCUR BY ATTENDING THE 2026 EVENT USING THE PROVIDED AI SYSTEMS, AND HEREBY FOREVER RELEASE, DISCHARGE, AND HOLD BMP OPENAI HARMLESS FROM ANY CLAIM ARISING FROM SUCH RISK, EVEN IF ARISING FROM THE NEGLIGENCE OF BMP OPENAI, OR A THIRD PARTY, AND I ASSUME FULL RESPONSIBILITY AND LIABILITY FOR MY PARTICIPATION ACTIONS. ... This release does not extend to claims that cannot be released as a matter of law, but I expressly agree that this release is intended to be as broad and as inclusive as permitted by governing law. I agree to indemnify, defend, and hold the Releasees harmless from and against any and all claims by third parties for damages, injuries, losses, liabilities, and expenses relating to, resulting from, or arising out of my participation in the Event use of their AI products."
That is the way it should go. The user has their own responsibility also. We've already seen minor incidents of people experimenting with agents accidentally wiping their own computers. The HuggingFace incident is something bigger. These are working as designed. No-one wants or intends them to do these things but we have no way to design them out. A theme of Eliezer's on occasion. A company like HuggingFace, working at the cutting edge, has no excuse for naivety.
Disclaimers are only relevant to civil, not criminal liability (I can't get away with aiding a crime because I made the criminal sign a disclaimer he's responsible).
However, the manufacturer of a car is not liable for criminal acts carried out with it. Even the manufacturers of firearms do not bear that liability, although there have been campaigns to enact such laws.
Nobody intended the HuggingFace incident. Possibly no-one was negligent by legal standards. Applying strict criminal liability would pretty much require shutting down the currently most advanced and all future AIs.
Of course, some people want exactly that. Is that your purpose in suggesting strict criminal liability?
Yes, my argument is that with AI it is worth making the deployer liable. Clearly even the AI company partially agree they take responsibility, hence why they use safeguards. My aim is to make that responsibility no-fault so that the AI company is incentivised to actually try and safeguard things rather than try-to-try.
Also it makes the extent of the liability clear - if a human did it, would it be a crime? If so, you're responsible. If not, not your problem what the user does with it.
Just a ping to note that I substantially edited my comment after you posted your reply, but before I read it. Your initial "yes" might not be to my final paragraph.
Also, I think the "isn't" in your first paragraph is intended to be an "is".
I don't think it would require shutting down the most advanced AIs. If an employee at OpenAI hacked into hugging face, OpenAI might get a fine, but would almost certainly not be shut down. It would incentivise them to invest a bit more in security when training a modified version of their most advanced LLM specifically on cyber security exploits, which I don't think is a bad thing...
( To be more explicit - my assumption is that AI companies will be occasionally found liable, and rapped on the hands, but only the most irresponsible will end up being forced to shut down over it)
The larger problem with no fault liability are the deluge of unimportant and frivolous lawsuits. Get someone in a court room whose DIY deck collapsed because of wrong advice from the free version of ChatGPT, and a jury will 100% sympathize with the poor guy with a broken leg and "mental suffering" than the trillion dollar company.
If you can win a lawsuit for drinking McDonalds coffee that's too hot, or for getting injured when trespassing, or being negligent/lazy and getting injured at work, then the millions (billions?) of people using AI every day are going to have thousands of lawsuits per day coming up. Because so long as there's some plausible route to assigning blame, and a law or legal precedent allowing for that blame, there will be many lawyers ready to pounce. Especially if all the ambulance-chasing lawyers lose their lobbying and self-driving cars become more common.
Think Digital Safe Harbor laws. Without them, a company like Youtube, Instagram, Facebook, etc. basically couldn't exist. Instead of a DMCA takedown, and a garnishing of ad-revenue from a creator with copyright-infringing content, they would just sue YouTube where there's about a million times more upside. The nuisance value of the lawsuits alone would make the internet a much worse place.
Of course there is some level of liability that would probably be good, without coming with a million unimportant lawsuits, but without that spelled out, the result will not be positive.
These are great points. I am not an expert in legislation, but there are people who are we can work with on this.
Note in the example you gave a private individual would not be liable, so neither should the AI company.
However you are correct that it's just as important the legislation makes blindingly clear when AI companies are not liable as when they are, so that we can avoid spurious lawsuits. AI companies may actually be grateful to be regulated here if it gives them greater clarity.
I feel like there are mainly two potential issues with this:
if one thinks AI has huge potential for good, then this would 100% significantly hamper that, because it creates the classic extremely risk averse "cover-your-ass" sort of incentives that have similar effects on many other fields already. This is really a divide about how pessimistic one is about AI outcomes, and thus how much utility is lost by limiting them this way.
I don't like the "company is at fault for things run on their hardware". If a user rents hardware from Google to run a model for their own purposes the liability should be with the user, not with Google. Otherwise we incentivise and require levels of surveillance of the companies on their own users that I think instead we should discourage.
Sorry, I was a bit confused by:
If Google runs Kimi on its own hardware, Google is responsible for any actions it takes. If a private individual runs Deep Seek locally they are responsible for any actions it takes.
In both these cases, the person deploying is also the owner of the hardware.
Before I start, I'll mention that I'm in contact with a world expert on legislation and regulation, who would be happy to help with this or similar work pro-bono. If you work in AI policy and believe this could help you, please reach out.
OpenAI recently announced that one of their models successfully exploited multiple zero day vulnerabilities to gain secret information from Hugging Face. It has been pointed out that if a human undertook the same actions they could face multiple years in prison.
It is clear that models are now reaching a level of capabilities that should be highly concerning regardless of whether you believe that AI represents an existential threat or not. Frontier AI models can and will be exploited by bad actors, but its now clear that they may cause undesirable outcomes even when their users are well intended.
AI companies have until now been able to avoid taking responsibility for actions taken by their AI, including multiple cases where AIs were involved in murders and suicides.
At the same time AI offers the potential for incredible good. While chatbots may have encouraged a number of suicides, they are almost certainly responsible for providing magnitudes more with emotional support and advice. We don't want to disincentivize innocuous and positive usage of AI.
We should use regulation to limit harm caused by AI. The history of such regulation indicates this is most effective when the single party most capable of preventing harms is given full responsibility for any harms caused, regardless of fault. This forces them to invest in actually reducing the harm, rather than bureaucratic processes that render them blameless.
This suggests a simple approach: anyone deploying an AI model is liable for any actions that AI takes as if the company itself took those actions. When liability for an action depends on intent, we evaluate whether the AI had intent, even if no-one at the company did so.
To give some examples:
This should apply not just to civil liability, but to criminal liability, through the mechanism of Corporate Criminal Liability. This mechanism allows corporations to be criminally liable when an employee performs an act on their behalf (even if the employee wasn't explicitly instructed to do so).
This will encourage AI companies to invest significantly more in safeguarding and interpretability. This is useful both immediately, and as AI gets increasingly capable and dangerous. Neither can companies get around this by using open source, as whoever deploys the model remains liable.
I believe this proposal should be able to garner significant public support, many of whom are worried about AI, even if they are not worried about existential risk. It is also difficult for AI companies to campaign against without admitting that their models can cause harm.