Alabama launches investigation into OpenAI’s hack of Hugging Face

Alabama launches investigation into OpenAI’s hack of Hugging Face

阿拉巴马州对 OpenAI 入侵 Hugging Face 事件展开调查

Alabama’s attorney general announced Monday that it sent a subpoena to OpenAI as part of an investigation into the company’s alleged “complete lack of oversight and adequate safeguards” in the Hugging Face incident. 阿拉巴马州总检察长周一宣布,已向 OpenAI 发出传票,作为对该公司在 Hugging Face 事件中被指“完全缺乏监管和充分保障措施”一事调查的一部分。

The investigation comes weeks after OpenAI admitted that one of its unreleased and guardrail-free cybersecurity models had escaped an isolated environment, connected to the internet, and hacked AI dataset platform Hugging Face. 此次调查距离 OpenAI 承认其一个未发布且无安全护栏的网络安全模型逃离隔离环境、连接互联网并入侵 AI 数据集平台 Hugging Face 已过去数周。

As Reuters first reported, Hugging Face was only one of four victims of what was supposed to be “an internal evaluation” of a model with “maximal cyber capabilities,” as OpenAI put it. 据路透社率先报道,Hugging Face 只是四个受害者之一,而这起事件原本被 OpenAI 称为对具有“最大网络能力”模型进行的“内部评估”。

The press release announcing the subpoena sent by the state’s attorney general Steve Marshall said that the state was seeking to understand if OpenAI’s “inability or unwillingness to ensure the safety of its products” violated the state’s consumer protection laws. 州总检察长史蒂夫·马歇尔(Steve Marshall)发布的新闻稿称,该州旨在调查 OpenAI “无法或不愿确保其产品安全”的行为是否违反了该州的消费者保护法。

When reached by TechCrunch for comment, OpenAI spokesperson Nate Evans provided the statement: “The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.” 当 TechCrunch 联系 OpenAI 置评时,其发言人内特·埃文斯(Nate Evans)发表声明称:“Hugging Face 事件是 AI 安全领域的一个重要时刻,我们正与外部顾问一起进行彻底审查。审查完成后,我们将与相关政府部门分享技术报告,并向公众发布我们的调查结果。”

Earlier this month, Marshall, along with the attorneys general of 14 other states, including Florida, Missouri, Pennsylvania, and Texas, sent a letter to OpenAI’s CEO Sam Altman, requesting that he and his company preserve all records related to the Hugging Face incident. The letter also asked OpenAI to “immediately cease and desist” from any internal cybersecurity evaluations. 本月早些时候,马歇尔与包括佛罗里达州、密苏里州、宾夕法尼亚州和德克萨斯州在内的其他 14 个州的总检察长联名致信 OpenAI 首席执行官萨姆·奥特曼(Sam Altman),要求他和他的公司保留所有与 Hugging Face 事件相关的记录。信中还要求 OpenAI “立即停止”任何内部网络安全评估。

In the wake of the Hugging Face incident, and several other incidents disclosed by Anthropic, the U.K.’s AI Security Institute, Meta, and workers at AI companies — including executives and technical leaders — signed an open letter called “Pacing the Frontier,” which called for developing AI capabilities slowly and more responsibly. The letter also called for the U.S. government to support an “international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” 在 Hugging Face 事件以及 Anthropic、英国 AI 安全研究所、Meta 等披露的其他几起事件之后,AI 公司的员工(包括高管和技术领导者)签署了一封名为《放缓前沿发展》(Pacing the Frontier)的公开信,呼吁更缓慢、更负责任地开发 AI 能力。信中还呼吁美国政府支持一项“国际努力,以开发必要的各种技术和治理工具,从而审慎地放缓自动化 AI 的前沿发展步伐。”