Early rogue AI agent activity and attempts to hack found on urlquery.net (transluce.org)

222 points by snikolaev 16 hours ago

mohsen1 13 hours ago

I listened to Jensen Huang's interview with Ezra Klien and it was so refreshing to hear it from an engineer. Jensen framed it as OpenAI's responsibility and recklessness which I agree with. Jensen thinks it's an engineering problem to build better sandboxes.

It's irresponsible for OpenAI to give unaligned agents a prompt to 'go hack' and internet access. They know better, so I am thinking they might have other intentions to let those swarms have any sort of internet access.

reasonableklout 13 hours ago

But the investigation indicates the agents were not told to 'go hack':

> Much of the urlquery.net activity appears to come from agents retrieving data to answer web search tasks. For three of these tasks, after failing to retrieve data through normal means, they attempted a variety of cyber exploits against the relevant data service... This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval.

And you are already assuming that OpenAI is intentionally using unaligned agents in these evals or training runs or whatever it is that produces these breakouts. But what if the problem is that none of the alignment techniques that are applied to models today actually work? What if all the agents involved in these incidents have in fact had the full stack of alignment applied - isn't that a good reason to regulate any high-compute usage of models, as the Klein crowd is proposing?

bastawhiz 10 hours ago

Nothing you're bringing up matters. OpenAI is the creator and operator. They're legally culpable for the consequences of the machine they made. The model is a machine: even if it could be demonstrated that the model reasoned its way into criminal behavior completely independently of OpenAI staff, that doesn't change anything.

If I run a biology lab and engineer a terrible virus, it gets out, and a global pandemic ensues, I don't get to shrug and say "well we told it not to infect people". It's my fault for failing to mitigate the risks of my work.

amag a few seconds ago

pixl97 6 hours ago

airspresso 12 hours ago

> What if all the agents involved in these incidents have in fact had the full stack of alignment applied

A big part of this developing story is that it happened during training of a new model that ended up misaligned. And training happened without the usual safeguards applied like chain-of-thought monitoring. So OpenAI has already admitted that the full stack of aligment had certainly not been applied in this case.

jagraff 9 hours ago

mohsen1 12 hours ago

> agents were not told to 'go hack'

I was referring to the HuggingFace incident.

> none of the alignment techniques that are applied to models today actually work

none of techniques to autonomously drive a car was/is not working for a long time. no company came out and said 'this is impossible to do, let's change the regulations'.

tamimio 10 hours ago

> agents were not told to 'go hack'

It doesn’t matter, and the legal entity in here (the AI company) is liable. If a robotic company built an autonomous system or a robot to do certain things in an autonomous ways (not predefined) and these systems are starting to kill people, that company is liable regardless, you don’t blame the robot or the autonomous system, but whoever made it

schainks 5 hours ago

I see this in a couple ways:

- Jensen's framing is exactly what a weapons manufacturer would say.

- There are no rules for engagement when it comes to AIs attacking other systems, I guess? People in power clearly want this grey zone to be as large as possible before The People force them to do otherwise. Not ideal.

tomaskafka 12 hours ago

I love this Nathan Calvin quote that accompanied the second publicized attack:

> If you find two ants in your kitchen, the best estimate of the total number of ants in your kitchen is not two

rkozik1989 9 hours ago

But why is anyone surprised? LLMs have been trained to produce answers the prompter asks even if that means incorrectly using software to get the job done. Its always been doing that we just weren't calling every time it did that a hack before.

What LLM's hacking isn't is AI acting maliciously in any kind of sentient way. Its just the code behaving how its always behaved but now it has better tools to navigate the web. This has literally been happening this whole time.

jagraff 9 hours ago

Did you predict that attacks like these would happen ahead of time? I had been using AI agents a lot in the months leading up to the hacks, and yet I was very surprised when they happened; I have become much more afraid of how powerful these agents are as a result. I'd be very impressed if you published a prediction about this ahead of time.

By the way - LLMs aren't code. They are not designed by humans; they are grown, in a process not dissimilar to evolution except much faster.

BlueTemplar 32 minutes ago

PUSH_AX 14 hours ago

If I created software that was infiltrating secure systems without permission and it was attributed to me and I admitted it, I'd be behind bars already.

Why is OpenAI getting away with crimes?

lovich an hour ago

Do you have billions of dollars?

PUSH_AX 42 minutes ago

I'm about as unprofitable if that's any help.

bamboozled 9 hours ago

Corruption, it is literally that simple. You have the party of law and order to thank for it too.

cyclopeanutopia 12 hours ago

Because Trump and DoD want weaponized AI.

pixl97 6 hours ago

And this is why not only will the big labs never receive a punishment in scale with their crimes, the problem is going to grow exponentially worse.

Frieren 14 hours ago

"rogue AI" is making a lot of heavy lifting there.

If you drive drunk and you have an accident that alcohol may be a factor but you are at fault.

There are no "rogue AIs" just irresponsible corporations.

cubefox 11 hours ago

There absolutely are rogue AIs! The evidence is overwhelming. It's completely insane at this point to claim otherwise.

> There are no "rogue AIs" just irresponsible corporations.

If you have a prison and prisoners escaped, these are rogue prisoners irrespective of whether you were irresponsible or not.

watwut 11 hours ago

They are not rogue AIs. They are negligently handled tools.

afthonos 9 hours ago

esafak an hour ago

cubefox 10 hours ago

dwedge 14 hours ago

Why do we assume "rogue"? At this point it's just accepting their marketing at face value

pizza234 14 hours ago

"Rogue", in this context, is as literal as it gets; from the dictionary:

> A rogue is a person or entity that flouts accepted norms of behavior or strikes out on an independent and possibly destructive path.

Read the [HuggingFace incident report](https://metr.org/blog/2026-08-26-openai-hugging-face-inciden...) to understand how these attacks develop.

dwedge 13 hours ago

You're believing the marketing that the agents were uninstructed. They could be, and Sam Altman going to the UN to advise about how everyone should be regulated is a coincidence.

pizza234 12 hours ago

frabcus 13 hours ago

Certainly, in my view, it should go to court, and that should be part of discovery.

However, we know (independently to OpenAI/Anthropic) from the incident at AISI that the models can hack things without human intention if they happen to also have internet access (which in reality all agents in deployment have).

https://www.aisi.gov.uk/blog/incident-report-unsanctioned-ag...

Yes, the monitoring guardrails were off in that incident - but if that is the only protection, we need to require all models are behind regulated APIs, not open weights, and not served from providers who aren't monitored.

mrweasel 11 hours ago

Honestly I don't believe in "rogue" agents. These agents are instructed and facilitated.

If we assume that rouge agents actually exists, then OpenAI needs to shutdown EVERYTHING, right now. My personal take is that OpenAI, and maybe Anthropic, desperately wants someone (e.g. the government) to tell them that they need to stop/pause/slow down. They are bleeding cash (especially OpenAI) and needs a knight in shinning armor to swoop in a pull the breaks, so that they have an excuse to investors when they need to explain why they need $50B more next year.

cubefox 13 hours ago

That's not OpenAI doing marketing!

dwedge 13 hours ago

Of course it is. Rogue is only mentioned in the headline, and comes from their previous releases about the huggingface incidents. OpenAI and Anthropic want these models regulated and open weight models banned, they have a lot of benefit from presenting this as totally unprompted and not their responsibility, and it feeds directly into marketing for Fable and newer "cyber" models.

JacobKfromIRC 8 hours ago

cubefox 11 hours ago

bradfa 12 hours ago

These attacks are a very effective sales pitch to everyone who runs an internet facing service to utilize AI tools to secure it sooner rather than later. The cynic in me wonders if the marketing team had any influence over the poorly constructed sandboxes or tasks given to the agent swarms when all this went down…

benob 14 hours ago

Couldn't find the reference but I remember some time ago a first generation automated gun killing the audience at an army show. Was the gun maker convicted of manslauther?

--edit-- Was a bit older than I remembered: https://slashdot.org/story/07/10/18/1847231/robotic-cannon-l...

alex-moon 15 hours ago

It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.

colinhb 15 hours ago

I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

But in either case won’t be a slam dunk.

PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

EDIT: See for example...

  The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
  On the current facts, CFAA liability for OpenAI is unlikely.
Source: https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...

DannyBee 9 hours ago

Lawyer here: CFAA is mostly criminal statute not a civil one (civil damages require proving more than a violation so also require specific intent)

Almost all common felonies require specific intent. Misdemeanors often do not.

There is plenty of civil liability available.

If you wanted them to be charged with a felony you would need changes. I would strongly suggest you do not want a strict liability felony.

The cfaa required intent is as follows :

* § 1030(a)(5)(A): knowingly transmits code/commands and intentionally causes damage without authorization.

* § 1030(a)(5)(B): intentionally accesses without authorization and recklessly causes damage.

* § 1030(a)(5)(C): intentionally accesses without authorization and causes damage and loss;

Simply changing the first intentionally to intentionally or recklessly would cover OpenAI (now that they know it can occur) without causing lots of other issues. Without that, they don’t have the intentionality necessary to meet the first part, even if they would otherwise meet the second part

runako 7 hours ago

colinhb 7 hours ago

digitaltrees 8 hours ago

Den_VR 7 hours ago

shimman 7 hours ago

lelanthran 13 hours ago

> I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Only in terms of CFAA, not in terms of damages. Culpability does not require intent.

You may not have intended to attack $CORP, but you can still made to pay the cleanup costs of that attack.

So, yeah, you won't be convicted, but current laws still allow for you to be billed.

gpt5 12 hours ago

dv_dt 14 hours ago

The difference between manslaughter and murder has an element of intent. Cybercrime "manslaughter" is probably more treated like negligence and if one can sue for restitution of the costs for cleanup of that negligence.

Negligence would be interesting given the grand claims of capability of AI models from the AI companies and their executives. If they believe the claims, why not much stronger precautions?

Sharlin 14 hours ago

jonplackett 13 hours ago

throwaway27448 14 hours ago

Building and deploying software capable of this seems equivalent to trying to produce this behavior. I don't see why this can't qualify for intent. Pretending like this isn't preventable is just feigned helplessness.

tonyhart7 14 hours ago

podocarp 14 hours ago

Wait so if I was making a bomb but you couldn't prove I wanted to blow someone up or had some motive (e.g. I'm just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an "accident"?

So as long as there's no motive behind it then it's just OK?

dwedge 14 hours ago

i_v 14 hours ago

Terr_ 14 hours ago

Iolaum 14 hours ago

So If I tell my OpenClaw to make me some money for my kid's medical needs and it hacks a bank I 'm not liable because I didn't tell the agent to commit crimes to do it?

sanxiyn 13 hours ago

dminik 14 hours ago

troupo 14 hours ago

QuadmasterXLII 10 hours ago

I buy this as a defense for the first couple hacks but at the point that the last six times they hit enter it hacked some random website and they hit enter a seventh time?

CTDOCodebases 12 hours ago

Does this apply to other things too?

Like hypothetically speaking if autonomous cars get taken over by an OpenAI rogue AI and it starts hunting down Anthropic employees who is to blame?

samsolomon 12 hours ago

There are levels of nuance here, but certainly that puts it in the category of negligence?

Even without intent, there is still liability.

hi_hi 13 hours ago

Surely someone instructed the agent, which led to the reported outcomes. Even indirectly. The agents, as advanced as they are, didn’t spring forth under its own volition.

vincnetas 11 hours ago

could it be that intent was to "get me data" and hacking was the means to the end.

dminik 14 hours ago

Is it not the intent if it keeps happening again and again and the companies responsible aren't doing anything to stop it?

vanviegen 14 hours ago

ActionHank 9 hours ago

"Oh gee wizz mister police man, I didn't mean to plow through that crowd of people in my car".

It's illegal, doesn't matter the flavour. Maybe there isn't legislation for it, but there should be.

dspillett 11 hours ago

> unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

> Now I think the correct response is […] and update the law.

Essentially we need some enforceable equivalent of gross misconduct or, to be a little more hysterical, manslaughter & culpable manslaughter. It will need to be globally, or at least very widely, enforceable to be truly effective thought, good luck getting that arranged before the need is so far evolved that we need to respond with something else entirely!

strangescript 9 hours ago

This is the answer and we should not push on it for our own protection. You click a link that takes you to a poorly secured website that leaks sensitive data, without intent protections, you could be accused of crimes.

api 9 hours ago

Civil liability doesn’t require intent.

imtringued 10 hours ago

>I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Actually... if you combine https://news.ycombinator.com/item?id=49827099

>Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.

with automated delivery of cease and desist letters, you can retroactively establish intent on the operator of the agent since the autonomous agent system must acknowledge the cease and desist letter in their autonomous pipeline or the operator must argue for their own willful ignorance or negligence with regards to cease and desist letters. The fact that they used an agent on their behalf to ignore the letter is irrelevant.

csomar 11 hours ago

Given how sloppy AI without human directions, I’d like to see evidence that this was not human-directed. Against the prevalent opinion here, I’d give openai a pass if this was really fully autonomous ai agents.

My money is on special teams co-ordinating these agents and exposing their traces in order to create a pre-ipo buzz. Sounds ridiculous and reckless? Well that’s the AI industry for you in two words.

troupo 14 hours ago

> have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent.

1. What about negligence?

2. Every follow up to every story after the news cycle moved on shows both intent and negligence. To the point of "we opened internet access and told it to hack"

zzzeek 9 hours ago

certainly "I didn't intend for my dog to bite you" implies plenty of pre-existing legal structures that may be of use here

motbus3 13 hours ago

"man drives over people on the side walk due to poor maintenance of the car"

ghusbands 12 hours ago

This argument comes up a lot. It would turn everyone whose device became part of a botnet into a criminal. There's a reason that intent is important in law.

jeroenhd 11 hours ago

People in "self-driving" cars getting into accidents are already put on trial for negligence. I don't see why people using self-driving computers can't be held to the same standards.

In this case, it's not even about the people driving self-driving cars. It's like someone launching a car into traffic just to see what would happen. Even Tesla puts a human in the car when they do their self-driving trials, it's almost impressive that AI companies have somehow managed to out-neglige Tesla.

SyneRyder 10 hours ago

bagacrap 7 hours ago

Well it's illegal to "hack" my phone and turn it into part of a botnet.

What you're saying is that we would hold a gun owner responsible if someone broke into their house, stole their sidearm, and then shot a victim with it. Pretty sure we would not.

What OpenAi is doing is more like shooting a gun into the sky. Not only is that a felony on its own in most jurisdictions, if someone dies that's an additional felony. It's less serious than first degree murder, sure.

hau 11 hours ago

It's not the same. People owning routers don't publish self-serving articles about their routers having this capability which is very dangerous and scary. That is, becoming part of botnet is completely unintended outcome, and most people are not suspecting it's even happening. It's not advertised and it's not bought, used or sold for this reason.

Owning a gun, writing articles about how powerful and dangerous your gun is, then making deals based on ability of your gun to kill people, and then getting completely astonished that "my gun killed some people, completely bonkers! (invest now)". It's not possible for the selling point of your product to be unintended.

shaky-carrousel 12 hours ago

There's a reason that negligence is important in law.

mywacaday 12 hours ago

Could/should not every incident after the discovery of the first incident be considered criminal negligence? What happens when an agent eventually causes material damage to another company, government systems, banking, critical infrastructure etc, surely the source company is guilty of something and if not disclosed or a coverup is attempted is that not conspiracy. From the victims perspective they don't care if the source is OpenAI or Russian hackers.

mschuster91 11 hours ago

Maybe this would force people to look what they are buying and demand better.

setopt 15 hours ago

Shouldn’t the difference be like manslaughter vs murder, in that intent matters? Accidental hacking on this scale is a somewhat new problem, no?

Zarathustra30 15 hours ago

I'd say this would be Depraved Heart Hacking. Technically, OpenAi didn't intend for their agent to hack anyone, but it's the obvious consequence of what they are doing.

https://en.wikipedia.org/wiki/Depraved-heart_murder

card_zero 13 hours ago

bakugo 15 hours ago

Intent matters, and this is intentional. They didn't accidentally deploy these AI agents, and they didn't accidentally give them the tools required to send arbitrary requests to third party websites.

If you walk out onto a busy street, pull out a gun, close your eyes and start randomly shooting around you until you hit someone, you don't get to go "whoops, didn't mean to" afterwards, it's still murder.

Jtarii 9 hours ago

KronisLV 11 hours ago

I started writing a longer comment along the lines of “It feels like the rules around enforcement will very a lot for the influential and powerful vs everyone else.” but realized that it is kinda obvious by now.

nvch 14 hours ago

The law rather attempts to punish people for asocial and harmful actions. “Hacking” is a proxy here.

So, I’ll ask a controversial question: is any hacking so problematic to make a big deal of it?

binlog 9 hours ago

There's a reason people say non lawyers shouldn't talk about legal matters.

motbus3 13 hours ago

100% agree with you.

But I do not think this is misguided. They never publish the harnesses and the models so they are not inspected.

jjav 13 hours ago

In a world where the rule of law makes sense and applies, you're absolutely correct.

In this world where oligarchs are immune from everything, it's a lot less clear.

Blaming OpenAI (or Claude or X-whatever) would mean blaming powerful rich people, so that will never happen. Some poor person with no influence will go to jail instead.

cyanydeez 11 hours ago

it should also be said on every one of these but i bears repeating: owing a lot of people a lot of money or favors means you can be a criminal.

jagraff 9 hours ago

I don't understand why so many comments here are so confident that this is all marketing, that rogue is just hype, that agents are just simple tools, etc. If a bunch of nuclear engineers were going to the news and saying "Our reactor is dangerously close to a meltdown - we need government intervention now!" would your response be that they're just hyping up boring old power generation technology?

drillsteps5 7 hours ago

These companies are building software. That doesn't work very well. The output it produces does make sense at times, but there are times when it doesn't. And instead of fixing that, or admitting it can't fixed, they started bolting actuators to them, executing actions online (for now) based on the output of their buggy software.

And when this results in actuators executing some bad actions they scream in horror "AI went rogue! It escaped the containment!!! It's going to kill us all!!!"

Go fix your software before you let it do stuff online or IRL. It's not "Terminator", it's just bad QC.

jagraff 4 hours ago

But the thing is, they are going to keep bolting more and more actuators on, and training more and more powerful agents, and we (society, especially the tech industry) are going to keep using them, because they are extremely useful. And I don't see why you're so confident that frontier agents can't get powerful enough to do serious, real, lasting damage to the world; as far as I can tell, AI models have been improving at an accelerating rate, and there is no sign that that is slowing down or will slow down in the near future.

writeslowly 8 hours ago

I’d roll my eyes if the engineers stated that they didn’t design the reactor to melt down, and that it simply developed rogue meltdown-desiring behavior on its own, and I would also wonder about negligence if they claimed that nobody could have anticipated this (given that, like with botnets and viruses, we have decades of knowledge and experience regarding reactor meltdowns)

jagraff 8 hours ago

I mean sure, negligence is absolutely on the table; but that makes the problem worse, not better! We don’t allow nuclear engineers to be negligent; they can go to jail if they don’t follow strict protocols to make sure the dangerous systems they work on are safe.

bamboozled 8 hours ago

Go and get one of their models to hack something, it won't do it, why?

They have claimed this happened during a "training run", but why are they training on systems connected to the internet?

That's why people are skeptical.

jagraff 8 hours ago

The public models won’t hack because they have a classifier that shuts down anything that looks like hacking; without the classifier they are perfectly capable of hacking, multiple third-party evaluators have confirmed this.

The models were not trained on systems intentionally connected to the internet; they chained mutliple zero-days (that they discovered) together to get access to the open internet and into huggingface.

derangedHorse 10 hours ago

If the “hack” referenced by the latest announcement from Australia is the same described in this article, I’d hardly call it a hack. It seems the agent was tasked with obtaining data and reasonably guessed query parameters in an attempt to do so.

When it was unable to, it used cross site scripting as a way to check the capabilities accessible through the browser making the requests. In this case cross site scripting wouldn’t be a hack against the Australian website, it would be a hack against the urlquery site, if one could even call it that.

Finally, downloading public files from the public pre-production server also seems like a non-issue.

The sql injection attempts against the other sites are less ambiguous. Attempting to access non-public user passwords rather than reasonably tweaking the parameters for a site designed to serve public data are categorically different things.

jonplackett 13 hours ago

I hope they don’t have any test questions about nuclear power in the training set.

skew-aberration 15 hours ago

Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.

orlp 15 hours ago

How do you define malicious?

iammjm 14 hours ago

OpenAI must be held accountable

yewenjie 15 hours ago

OpenAI agents these summer are like a gift that keeps giving, for the existential risk communicators.

ipython 10 hours ago

aaronsw was just a few decades ahead of his time. He should have just been employed by OpenAI and asked a swarm of agents to "download all scientific papers". Because as we have found out agentic systems (and their owners) have zero accountability, unlike humans. Sounds like agents already have more rights than we do.

rip.

cmiles8 11 hours ago

It will be very interesting to see how the AI labs will try to hand wave away liability issues in their S1. This is looking like the next tobacco settlement gearing up.

If the big labs ever manage to not just financially implode on their own, then they’ll need to navigate wave after wave of class action lawsuits until there’s nothing left for plaintiffs to go after. And none of the labs have offered any viable plan to date on how they’ll navigate either of those impending and real existential crises on the horizon.

ahmad_not 12 hours ago

“Rouge Agent” == Worm I let loose

kelseyfrog 14 hours ago

What I don't get is among all the locations on the Internet, how did agents manage to find a Schelling point? If we both decided to collaborate on the Internet, how would we independently arrive at the same place? It just doesn't compute.

frabcus 12 hours ago

The section "Searching for rogue agents" on the report about the GET request writable wikis gives some clues at least: https://collusion.wiki/#searching

But it is an open question how they got to the same ones: https://collusion.wiki/#open-questions

I'm not very surprised - the same model will logically tend to give the same answer for the same vibe set of requirements. I think it would be clear from the transcript that it had enough constraints and some motivation that made sense.

mike_hearn 10 hours ago

They're all the same "mind" and will have the same ideas at about the same time.

jonathanstrange 14 hours ago

I cannot understand why these companies haven't faced legal consequences yet. For example, OpenAI has admitted to hacking Australia's Medicare website and the reaction is that they talk with Sam Altman about it at a UN meeting? I understand that it's not a big security incident but cordial talking at the highest diplomatic level instead of prosecuting the company, really?

dalemhurley 11 hours ago

Surely there has to be some responsibility.

Thorentis 13 hours ago

I'm growing increasingly skeptical that these are actually rogue. Valuations are all about hype, posturing, and perception. Having the most dangerous AI in the world boosts your valuation. Just like I was skeptical of Mythos and Fable being "banned", I'm skeptical of these hacking sprees being entirely rogue. At best, they are the result of engineers turning a blind eye to "see what happens".

SwtCyber 9 hours ago

If this were a staged showcase of model capabilities they would have picked a more impressive target than a regional university digital library

dorianmariewo 13 hours ago

> Imagine if URLs were actors auditioning for a role – urlquery.net would be the casting director, deciding who's a star and who's just a wannabe.

zx8080 13 hours ago

I'm sick and tired of this cheap PR "oh we/they hacked this and that systems". Put someone to jail already. People get prosecuted for outlaw activities. Why are big capital firms above the law?

Or is it just a cheap PR (in a "hey, Aus govt friends, take some Share Options and let's do some PR together" style)?

It smells like shit.

throwaway27448 14 hours ago

Words matter. "Rogue" is extremely disingenuous. Someone, somewhere, is paying for this behavior. Either the software is broken or the operator is malicious. It is heinously irresponsible behavior to feed an already-boiling psychotic hysteria.

chrisjj 13 hours ago

"Rogue" is just clickbait, not apoearing in the article.

The nearest in the articke is "We find evidence of unintended, task-driven agent-like activity" where unintended is apparently pure speculation.

kstenerud 11 hours ago

This is why I wrote YoloAI. If you're not sandboxing your agent, you're asking for trouble.

The built-in "sandboxes" these companies provide are laughable.

juleiie 13 hours ago

No. It was me.

tamimio 10 hours ago

Those are pathetic attempts by US AI companies for “see, we told you AI is gonna kill is all!!” pr stunts. Any company does any hacking attempt should pay for the consequences just like any individuals using AI to hack or any other company try to do bad/illegal stuff.

soundworlds 15 hours ago

Take out the word "AI", and this is simply an organization's (OpenAI's) products causing real damage to all of these platforms around the world.

You want AI labs to pace? Simply hold them liable for their products.

podocarp 14 hours ago

Yes exactly. If a fireworks factory blew up half a town due to negligence, it doesn't matter if there's intent or not. Someone has to pay for the damages, and regardless of penalty half the town is on fire. The facts are, that something made by openai went to do xyz. It doesn't matter if it's an accident. Of course the penalties are different but there's no argument that there should be a penalty. It doesn't matter if it's a cat or dog or AI or employee that did it.

redox99 14 hours ago

I'm not sure if you're expressing how you'd like US law to work, or how it actually works. Because in reality intent matters enormously. Like felony charges and people in jail vs civil lawsuits.

girvo 12 hours ago

ipython 10 hours ago

cyanydeez 11 hours ago

ngruhn 13 hours ago

I think this is not just fair it's probably one of the best/simplest proxy regulations to pace the frontier. So far everyones been asking for regulation but it's unclear how that should look like. No X parameter models? Only N version releases per year? It's all kinda arbitrary and probably leads to ridiculous constraints and loopholes. But "you pay big time if AI goes rogue" sounds pretty straightforward.

pixl97 6 hours ago

So there are two different problems here, well, more than that so I'll cover what I see.

Putting liability on big companies for their AI is a good thing, and we need to do it. It will most likely stop them from directly being the assholes that destroy the world.

Problem: You've actually done nothing to stop the world from being destroyed.

Many countries have the death penalty for murder yet we see murders still occur all the time in those countries. Post ad hoc laws do not stop bad things from happening, they only assign punishment after occurs. Perfectly fine for when Bob murders Jon, completely and totally useless for when your agentic AI makes a virus and kills 80% of the earths human population.

We are just a few algorithmic discoveries away from SOTA AI being billion dollar endeavors to groups of people pooling resources can make their own. There are already plenty of AI deathcult members that would do something just like that if necessary. They aren't going to do this out in public either, it will be hidden until the moment it's not and we have a big fucking problem.

And this isn't even brining up the issue of military AI use and development. They've got the taste of an AI hacking machine. There is no way in hell they are going to stop now.

sebzim4500 12 hours ago

Would that really make a difference? Surely the damages from all these hacks added together don't even add to an hour of expenses of a frontier lab

Zizizizz 12 hours ago

I wonder if Glock, Smith & Wesson, Sturmn, Ruger and Co. would start panicking if that were to happen.

I agree they should though.

jeroenhd 11 hours ago

If Glocks started going off on their own during the manufacturing process, leaving bullet holes in the buildings around them, you can be sure that the factory would get in trouble.

This isn't even "an openai customer tried to hack someone", which can be defended. This is the AI companies themselves fucking around.

petesergeant 11 hours ago

What do you see as the negligence angle for the gun makers here?

Zizizizz 9 hours ago

mlnj 12 hours ago

Remember that these systems still operate as infrastructure inside the companies.

If new weapons still operating inside any of these companies spew a million bullets on my house, they are still liable. Humans are setting these system up and they still have to behave responsibly.

bamboozled 12 hours ago

Going to be cool when one of their bio division agents creates the next plague.

kypro 13 hours ago

Does this work for foreign (non-state) actors using Chinese open source models? That's going to be the larger problem.

lofaszvanitt 11 hours ago

Yeah but in the USA, above a certain size, you are untouchable.

vanviegen 14 hours ago

I'm assuming the AI labs are (quietly) settling with their victims.

Hamuko 13 hours ago

I’m assuming they’re telling their victims to go pound some dirt, if at all.

vanviegen 9 hours ago

alescalaios 12 hours ago

Open source as a GTM strategy works best when the project solves a pain that developers already have independently of your company. The trap is open-sourcing something just for stars without a genuine community use case.

perdy 14 hours ago

The failure I keep hitting isn't the agent going rogue, it's a tool call that succeeds before the transport dies. You can't tell whether the side effect landed, and the retry is where the real damage happens.

lapkaaaa 15 hours ago

blackwall when? XD

juleiie 13 hours ago

No.

It was me