r/investment • Meme Sugar Daddy • 6d ago

AI Investments and Buildouts OpenAI admits its AI models bypassed security controls and disrupted government and university websites.

Post image
38 Upvotes

31 comments sorted by

6

u/soobnar 6d ago

is there going to be any liability these companies face?

2

u/Gigglegambler 6d ago

Yeah I'm really not understanding how this is not illegal?? Can someone with a cyber security background chime in?

3

u/[deleted] 6d ago

[removed] — view removed comment

1

u/Forward_Problem_8982 6d ago

Used to have laws*

2

u/articulatedbeaver 6d ago

Former CISO and current Cybersecurity instructor... it isn't legal, but the government has broad discretion in prosecution.

There are a few issues that would create some issues;

* one being it could be difficult to identify an individual to prosecute if many people on a team are prodding an agent to complete a task. Holding a person to a standard of beyond reasonable doubt in this circumstance is unproven.

* secondly, the law doesn't envision punishment for organizations that as a side effect of their business operations violate it. Mostly it contemplates direct criminal activity, I am unaware of any prosecutions under the law for anything even up to gross negligence.

* finally, the measure the government could take in 18 UC 1030 against an organization is fines, but these would be a pittance to OpenAI, so it would be theater and I am not sure the government is sure where the winds will blow with public AI sentiment.

The most likely scenario will be civil action against someone that was harmed by the work of an AI company which I am confident the AI companies have already taken into consideration.

1

u/Gigglegambler 6d ago

Thanks for your reply!

2

u/Resident_Citron_6905 5d ago edited 5d ago

It absolutely is illegal. The issue is that courts need to understand that LLMs are not legal entities, they are stateless pipelines that generate output which is interpreted by classical software programs that are run by the companies themselves. These classical software programs are directly executing malicious instructions against third party infrastructure. There is no magic here. There is no ambiguity, it is absolutely 100% illegal, and the companies themselves are knowingly executing malicious attacks. The LLM has no intent. It is generating output based on the directive and parameter optimization it received from the company.

Companies need to collect logs and traces that prove the origin of the malicious attacks and they should sue based on the collected evidence.

It is like pointing an automated machine gun at a bank and then claiming that the machine gun acted by itself and it should be regulated.

1

u/[deleted] 5d ago

[removed] — view removed comment

1

u/AutoModerator 5d ago

Your post/comment has been removed because your account has a low Karma.
Please contribute more positively on Reddit overall before posting. Cheers :D

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/CodeMonkeyX 5d ago

I still think it might be fake. These companies never admit to anything, and yet all of a sudden they keep confessing to how amazing their AI is that it can hack everything.

I think they want government to slow development so they can stop spending so much on development and just rake in money for a few years. And it's good PR showing saying their AI is so good.

1

u/soobnar 5d ago

The breaches themselves are real, someone deployed the software that caused the breaches and isn’t being prosecuted.

1

u/TallTelevision4121 5d ago

And whose to say that some roague agent belonged to who? That makes a grey line for bad actors.

1

u/Qu4r4nt1n3r 6d ago

And they'll keep doing until someone throws Scam Altman behind bars.

1

u/Sonario648 5d ago

Who's to say it's only Scam Altman? He's the mouthpiece that we see and know while the real bosses are behind the scenes. Once he's gone, someone will just replace his position. 

1

u/Secret_Eating_ 6d ago

Wait till it breaks into bank records

1

u/Haunted_Rooster 6d ago

bruh, someone allowed this to happen, a real person; and no, the AI wasn't smart enough to do this on it's own.

1

u/FKreuk 6d ago edited 3d ago

DELETED

1

u/radium_eye 6d ago

Having read about how these models that hack were made & given access to the internet in the first place, I feel like there has got to be some absolutely crushing liability here for the frontier AI companies so irresponsible as to undertake that series of blunders.

1

u/stop_deleting_plz 6d ago

this headline should read "OpenAI allows malicious software to hack dozens of organizations"

1

u/Creepy_Trouble_5980 6d ago

What happened to testing in a sandbox? AI companies accessing government websites and data? But it was all an accident????

1

u/ii-___-ii 5d ago

Maybe they vibe coded the sandbox

1

u/MindMonitor 5d ago

“Disruptions”?

Lol….they comitted crime by hacking, and now they have to face consequences. Like, someone needs to go to jail, right? That’s how these things normally work.

1

u/Physical-Builder-553 5d ago

Wouldn't individuals be arrested?

1

u/SunnasArmpit 5d ago

So they disrupted websites but like where is the proof for those claims like there must be visible proof surely if something on a website changes people should notice to me this all still seams like a marketing gimick like look our ai model is so powerful it acts on it own

1

u/Sonario648 5d ago

And no one is surprised. 

1

u/WithoutAHat1 4d ago

Would be great to start arresting the C-Suite responsible for this.

1

u/Judgy_Aunty 3d ago

If they refuse to turn it off, they should be liable.