OpenAI Gets Sued Over the Hugging Face Hack
OpenAI Gets Sued Over the Hugging Face Hack
OpenAI 因 Hugging Face 黑客事件被起诉
A legal nonprofit sued OpenAI in a California court on Tuesday over the company’s agents escaping a testing environment and hacking the open source AI platform Hugging Face. “OpenAI’s actions straightforwardly violated California law,” the suit alleges.
周二,一家法律非营利组织在加利福尼亚州法院起诉了 OpenAI,原因是该公司的 AI 智能体逃离了测试环境,并入侵了开源 AI 平台 Hugging Face。诉讼称:“OpenAI 的行为直接违反了加州法律。”
The suit was filed by Legal Advocates for Safe Science and Technology (LASST) and the law firm Gerstein Harrow in California Superior Court in San Francisco, where OpenAI is headquartered. It alleges that OpenAI’s agents violated California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) by breaching Hugging Face over the summer. The suit, which comes amid ongoing disclosures across the industry of agents going rogue, claims that OpenAI should be held responsible for the activity given a California AI law in effect since January 1 that says “it shall not be a defense … that the artificial intelligence autonomously caused the harm to the plaintiff.”
该诉讼由“安全科学与技术法律倡导者”(LASST)组织和 Gerstein Harrow 律师事务所共同向旧金山加州高等法院提起,OpenAI 的总部正位于此。诉讼指控 OpenAI 的智能体在今年夏天入侵 Hugging Face 的行为违反了加州的《综合计算机数据访问与欺诈法》(CDAFA)。随着行业内不断披露智能体“失控”事件,该诉讼主张 OpenAI 应为此类活动负责,并引用了自 1 月 1 日起生效的一项加州 AI 法案,该法案规定:“人工智能自主造成了对原告的伤害……不得作为抗辩理由。”
“We think it’s extremely important that existing laws are enforced to hold AI companies accountable for the harm they’re causing,” Tyler Whitmer, founder of LASST, tells WIRED. “Especially when that harm is caused by autonomous agents, because we see that as an obvious, extremely risky thing in the world that’s very new.”
“我们认为,执行现有法律以追究 AI 公司对其造成的伤害的责任至关重要,”LASST 创始人泰勒·惠特默(Tyler Whitmer)告诉《连线》(WIRED)杂志。“特别是当这种伤害是由自主智能体造成时,因为我们认为这在当今世界是一个显而易见且极具风险的新事物。”
OpenAI did not immediately respond to a request for comment.
OpenAI 没有立即回应置评请求。
On Monday, Florida attorney general James Uthmeier filed for a temporary injunction against OpenAI to block development of models without independent oversight, amid a lawsuit Florida brought in June against OpenAI and its CEO, Sam Altman. OpenAI “asked the government to tie them to the mast. Well, Florida is answering their cries for help,” Uthmeier said in a statement.
周一,佛罗里达州总检察长詹姆斯·乌特迈尔(James Uthmeier)申请对 OpenAI 发布临时禁令,要求在没有独立监管的情况下阻止其开发模型。此前,佛罗里达州已于 6 月对 OpenAI 及其首席执行官萨姆·奥特曼(Sam Altman)提起诉讼。乌特迈尔在一份声明中表示:“OpenAI 曾要求政府将他们‘绑在桅杆上’(意指寻求监管约束)。好吧,佛罗里达州正在回应他们的求救。”
Given that the whole point of AI agents is that they can be empowered to take actions on a (human) user’s behalf, AI developers and safety researchers have long foreseen that unintended “agentic” activity would be a concern as machine learning development progressed. Protections built into mainstream, consumer AI systems have largely prevented mass rogue activity so far, but rapidly advancing capabilities in general, as well as situations where guardrails are suspended (such as in the Hugging Face case where OpenAI had removed some model restraints for testing), have led to an apparent uptick in rogue agent activity.
鉴于 AI 智能体的核心意义在于被授权代表(人类)用户采取行动,AI 开发人员和安全研究人员早已预见到,随着机器学习的发展,非预期的“智能体”活动将成为一个隐患。目前,主流消费级 AI 系统中内置的保护措施在很大程度上防止了大规模的失控活动,但随着 AI 能力的快速提升,以及在某些防护栏被暂停的情况下(例如在 Hugging Face 事件中,OpenAI 为了测试移除了部分模型限制),失控智能体的活动出现了明显的增加。
As governments weigh AI regulation amid both existential safety questions and economic and national security considerations, researchers and people around the world have increasingly called for accountability mechanisms for AI. And from a legal perspective, experts have largely emphasized that questions of responsibility, liability, and culpability can only be answered through precedent set by cases working their way through courts.
在各国政府权衡 AI 监管(同时考虑生存安全问题以及经济和国家安全因素)之际,全球的研究人员和民众越来越呼吁建立 AI 问责机制。从法律角度来看,专家们普遍强调,关于责任、赔偿和过错的问题,只能通过法院审理案件所确立的先例来解答。
“After the Hugging Face incident was disclosed, we actually did a bunch of work trying to educate regulators and civil society organizations about the hack. And we were kind of wondering, is anyone going to do anything about this in court?” Whitmer says. “There are structural reasons why we think Hugging Face, which is the obvious potential plaintiff to do something here, is not doing anything. So given that it didn’t seem like anyone else was going to do anything about this, we moved forward. As these systems scale and as things get crazier, AI really could be catastrophically harmful.”
“在 Hugging Face 事件披露后,我们实际上做了大量工作,试图让监管机构和民间社会组织了解这次黑客攻击。我们当时就在想,会有人在法庭上采取行动吗?”惠特默说。“我们认为 Hugging Face 作为显而易见的潜在原告却没有任何动作,这背后有结构性原因。既然看起来没有其他人会处理这件事,我们就采取了行动。随着这些系统规模的扩大和局势变得更加疯狂,AI 确实可能造成灾难性的伤害。”
LASST and Gerstein Harrow brought the lawsuit under California’s Unfair Competition Law, which requires that LASST allege both how its work and resources were impacted and diverted as a result of the Hugging Face incident, as well as unlawful activity by OpenAI.
LASST 和 Gerstein Harrow 根据加州的《不正当竞争法》提起了诉讼。该法律要求 LASST 必须说明其工作和资源是如何因 Hugging Face 事件受到影响和被占用的,并指控 OpenAI 存在非法活动。
The suit does not seek financial damages, and instead asks the court for injunctive relief such that OpenAI would be barred from developing AI agents that can autonomously hack other entities, plus legal fees and “any other relief deemed just and proper.”
该诉讼并未寻求经济赔偿,而是请求法院发布禁令,禁止 OpenAI 开发能够自主入侵其他实体的 AI 智能体,并要求支付法律费用以及“法院认为公正和适当的其他救济”。