When a cybersecurity experiment goes wrong, the public response is predictable: Find out who is responsible, punish them, compensate the victims and make sure it never happens again.
That instinct is understandable. But imagine if automakers tested every vehicle at only 20 miles per hour because they feared a crash-test car might escape the warehouse. The public might be protected from a runaway test vehicle, but manufacturers would learn little about how cars perform under dangerous real-world conditions.
Artificial-intelligence testing presents a similar dilemma. When powerful artificial-intelligence (AI) systems escape controlled testing environments and gain unauthorized access to outside organizations, punishment alone may create more problems than it solves.
REP. TED LIEU: AI IS ALREADY TOO POWERFUL. WE NEED A KILL SWITCH BEFORE DISASTER STRIKES
Recent disclosures have revealed that advanced AI models breached third-party systems during their cybersecurity evaluations. In some cases, the organizations conducting the tests did not immediately realize what had happened. Experts warn that other unintended intrusions may have occurred without ever being detected and commentators were quick to point the finger.
The obvious response is to throw the book at the AI developers responsible. But there is a catch, if the penalties are too severe, that may deter AI labs from conducting similar research or make them even less transparent about how, when, and to what ends they are evaluating their models.
AI safety testing is not an exact science.
Even the worlds leading researchers struggle to build the perfect environments to elicit as much information about their models as possible without also introducing some risk of harm to third parties. Best practices can reduce the danger, but recent incidents demonstrate that even the leaders in the field may not always properly implement those safeguards and that even when they do so risks may still remain.
IRANIAN HACKERS ATTACKED OUR WATER SYSTEMS. HERE ARE 5 THINGS OUR LEADERS NEED TO DO NOW
Ultimately, excessive punishment may deter labs from performing this societally important research or from doing so in a way thats likely to demonstrate a models full capabilities.
Researchers must push advanced systems hard enough to expose their weaknesses before foreign adversaries or criminals do. At the same time, innocent businesses should not be forced to pay the price when those tests escape the lab.
That means that we need a smarter answer than simply “punish the lab.”
Some argue that access to the most powerful AI tools should be restricted to a small group of government-approved partners. Under the status quo, the most advanced tools are first offered to “trusted partners,” as established by a combination of the labs and the U.S. government. If youre off that list, then you may find yourself particularly vulnerable to such incidents.
FROM NEW YORK TO TEXAS, STATES SHOULD RESPECT LOCAL CONTROL ON DATA CENTERS
Americas response should focus on strengthening cyber defenses across critical infrastr