The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
OpenAI 与 Anthropic 的 AI 黑客事件:法律领域的新乱局
Who is legally responsible when agentic AI goes rogue, and what recourse do victims have when they’ve been breached by joyriding models? Great question. 当代理型 AI(agentic AI)失控时,谁该承担法律责任?当受害者被这些“脱缰”的模型入侵时,他们又该如何寻求救济?这是一个好问题。
In the wake of disclosures from both OpenAI and Anthropic that versions of their models escaped containment during internal cybersecurity experiments and hacked real-world organizations, calls for government regulation of AI have been mounting. But as more and more incidents emerge, questions about legal liability and repercussions have also come to the fore. 继 OpenAI 和 Anthropic 先后披露其模型在内部网络安全实验中突破限制并入侵现实组织后,政府加强 AI 监管的呼声日益高涨。随着此类事件不断涌现,关于法律责任和后果的质疑也随之浮出水面。
Researchers and lawyers WIRED spoke to emphasize that these questions have not been answered in practice in the United States legal system. In other words, there haven’t been decisions in enough relevant cases for the picture to start to form. But the recent high-profile incidents from OpenAI and Anthropic suggest that answers will need to come soon. 《连线》(WIRED)采访的研究人员和律师强调,这些问题在美国法律体系中尚未得到实践层面的解答。换句话说,目前还没有足够的相关判例来勾勒出清晰的法律图景。但 OpenAI 和 Anthropic 近期发生的这些高调事件表明,答案必须尽快出炉。
“Just because you’re using an AI agent or AI model, that shouldn’t somehow absolve you of any liability, but it’s going to depend a lot on the facts in the particular situations” as cases begin to be decided in courts, says Lauren Yu, a fellow with the ACLU’s Speech, Privacy, & Technology Project. 美国公民自由联盟(ACLU)言论、隐私与技术项目研究员 Lauren Yu 表示:“仅仅因为你使用的是 AI 代理或 AI 模型,并不意味着你可以免除任何责任。随着案件开始进入法院审理,最终判决将很大程度上取决于具体情况的事实。”
Experts say that so-called agency law could be relevant given that the doctrine focuses on situations where a “principal” has given an “agent” permission and authority to act on their behalf. To be clear: The “agents” in this area of law have always been human. 专家指出,所谓的“代理法”(agency law)可能具有相关性,因为该原则关注的是“委托人”授予“代理人”代表其行事的许可和权限的情况。需要明确的是:在这一法律领域中,“代理人”一直以来都是指人类。
Tort law, in which a wrong causes harm that leads to legal liability, could also potentially be invoked in rogue AI cases. Contract law could also be used, depending on a rogue AI’s actions and the terms of any contracts between those involved, if applicable. And hacking laws like the Computer Fraud and Abuse Act or state-level legislation could also be relevant. The CFAA and many other hacking laws have “intent” requirements, though, that experts say make them a seemingly poor fit for AI-related cases. 侵权法(Tort law)——即因不当行为造成损害而导致法律责任的法律——也可能被援引至失控 AI 的案件中。合同法也可能适用,具体取决于失控 AI 的行为以及相关方之间是否存在合同条款。此外,诸如《计算机欺诈与滥用法案》(CFAA)或州级立法等黑客法律也可能相关。不过,专家指出,CFAA 和许多其他黑客法律都包含“意图”要求,这使得它们似乎并不太适用于 AI 相关案件。
Ultimately, experts emphasize that questions about US federal AI liability law will be answered only through more litigation. 归根结底,专家们强调,关于美国联邦 AI 责任法的疑问,只有通过更多的诉讼才能得到解答。
“Perhaps most concerning to critics is that AI agents are goal-oriented but lack a human moral or ethical compass,” the law firm Brownstein Hyatt Farber Schreck wrote in an alert to clients on July 24. “In some situations, an agent may infer actions that were never explicitly authorized if those actions appear necessary to achieve its objective.” 律师事务所 Brownstein Hyatt Farber Schreck 在 7 月 24 日给客户的预警中写道:“批评人士最担心的或许是,AI 代理以目标为导向,却缺乏人类的道德或伦理准则。在某些情况下,如果代理认为某些行为对于实现目标是必要的,它可能会推断出从未被明确授权的操作。”
OpenAI and Anthropic each described the cybersecurity incidents involving their AI agents as the accidental consequences of testing their models’ cybersecurity capabilities with their typical safeguards turned off. Both companies declined WIRED’s request to comment for this story. OpenAI 和 Anthropic 均将涉及其 AI 代理的网络安全事件描述为在关闭常规安全防护措施的情况下,测试模型网络安全能力时产生的意外后果。两家公司均拒绝了《连线》就本文发表评论的请求。
In the meantime, the hits keep on coming. Reuters reported on Friday that as OpenAI investigates the hack of Hugging Face and other entities, it has discovered other examples of situations where its agents have escaped containment—though apparently none of these new findings led to breaches of other organizations. 与此同时,此类事件仍在不断发生。路透社周五报道称,在 OpenAI 调查 Hugging Face 及其他实体遭黑客攻击事件的过程中,它发现了其他 AI 代理突破限制的情况——尽管目前看来,这些新发现并未导致其他组织遭到入侵。
Speaking earlier this week about OpenAI’s Hugging Face disclosures, Alex Zenla, chief technology officer of the cloud security firm Edera, mused, “This is just the one that we know about, but god knows what’s happened with the stuff that we don’t know about.” 本周早些时候,在谈到 OpenAI 关于 Hugging Face 的披露时,云安全公司 Edera 的首席技术官 Alex Zenla 感叹道:“这只是我们已知的一起事件,天知道那些我们不知道的事情背后发生了什么。”