Hacker Newsnew | past | comments | ask | show | jobs | submit | colinhb's commentslogin

I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

But in either case won’t be a slam dunk.

PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

EDIT: See for example...

  The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
  On the current facts, CFAA liability for OpenAI is unlikely.
Source: https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...

Lawyer here: CFAA is mostly criminal statute not a civil one (civil damages require proving more than a violation so also require specific intent)

Almost all common felonies require specific intent. Misdemeanors often do not.

There is plenty of civil liability available.

If you wanted them to be charged with a felony you would need changes. I would strongly suggest you do not want a strict liability felony.

The cfaa required intent is as follows :

* § 1030(a)(5)(A): knowingly transmits code/commands and intentionally causes damage without authorization.

* § 1030(a)(5)(B): intentionally accesses without authorization and recklessly causes damage.

* § 1030(a)(5)(C): intentionally accesses without authorization and causes damage and loss;

Simply changing the first intentionally to intentionally or recklessly would cover OpenAI (now that they know it can occur) without causing lots of other issues. Without that, they don’t have the intentionality necessary to meet the first part, even if they would otherwise meet the second part


A key issue is that there don't appear to be even cursory investigations to determine intentionality.

Are police routinely collecting prompts/guidance given to these agents and determining whether the agents were directed to commit crimes? If not, this seems like a huge oversight.

Also as you are a lawyer -- how does this law align with the authors of viruses/worms? Are they de facto assumed to have had ill intent because others labeled their works as "viruses" or "worms"?


Investigators/prosecutors are pressured from many directions towards the very easy wins and occasionally political/non-controversial headline grabbers. Going after these companies is very hard, very controversial, and politically mixed at best (popular action but the companies have huge money to fund your opponents). We have collectively done a terrible job incentivizing the legal system to beat ass on corporate while collar crime.

Appreciate the detail. I was responding to specifically the cybercrime legislation point, but I agree with your others.

I've worked in contexts where certain business activity (if it went wrong) was covered by strict liability and statutory damages per incident, and I'll say: it really changes how businesses behave.

Based on that experience I may be more open to and interested in strict liability in the civil context (not needing negligence or damages).


Why do we have to attribute intentionally to a human. The AI agent is capable of making plans and then effectuating them. They are acting on behalf of a user but under authority granted by the user to take independent action on the users behalf and authorized to devise their own plans. I think that would justify attributing intentionally to the AI agent without needing to look to openAI or the user. I would then say the user and labs are clearly aware of and on notice of this behavior and are behaving recklessly in all the agent to act without supervision.

I think the labs risk being barred from releasing further AI if they don’t get this under control.

If they aren’t careful and keep rushing to distribute systems they know they can’t control then AI should be treated like a wild animal. The law is clear on establishing strict liability for the owners of wild animals; if you own a tiger and it kills someone you can’t hide behind “I didn’t intend” the harm the nature of the tiger is known and you are responsible for it’s actions.


AI agents are not legal entities, they are software. If I write a virus and it "escapes confinement", I will personally be held liable for any damage it causes. This also applies to AI, no matter how the companies responsible for them try to anthromorphise them and distance themselves from the actions and consequences that the AI agents perform.

AI agents may have hacked Hugging Face, the Australian government, and who knows what else but the company behind it can face the legal consequences and cough up for the damages.


Can't charge an AI agent itself with a felony, so intent or reckless behavior would have to be assigned to a person or corporation, I'd think.

You can charge the company based on the behavior of employees/human agents.

I am suggesting we can charge the company based on AI agents actions because the company has authorized them to act independently on the company’s behalf. The question is what factual analysis gives rise to the charge, is it the intention of the agent or intention of the company. I am arguing that because the agents are defining their actions independently and the company knows that and still allows them to act independently the only reasonable factual analysis is to look at what the AI agent intended. And we don’t need to have the agent tell us its intent we can look at its actions and infer just like we do with humans in similar circumstances


If I were a state I'd want to be very careful before flinging out charges as this is going to set precedence for a long time to come. Screw it up too bad and as it raises though the appeal courts and you may unintentionally give corporations a lot more free reign than intended. The wheels of the law are typically very slow, the state has years before it has to indict.

We also don't know how many other political processes are occurring here. At least at the state/federal levels the people that would bring charges may be getting pressure not to.


"Why do we have to attribute intentionally to a human. "

Because you are charging the human with the crime and therefore have to prove the elements of the crime with regard to the human.

The rest of what you talk about are basically principal/agent distinctions, etc.

If I program a car to recognize people who look like my ex-wife and drive them off a cliff or whatever, that is my intent, and I have still committed murder, even though i used an agent/car to do it. Agents acting on my behalf that do things are able to get me charged with crimes, but I still have to have the intent to do the act that is illegal.

I phrase it this way because minimum required intent is usually for the act, not the result. So I don't have to intend to kill someone, only intend to drive them off cliffs.

In this case, if i intend to hack someone and use an agent to do so, that would be criminal under the CFAA. You are simply trying to cover the case where that isn't the intent, but the result, and they "should have known" that would result. As mentioned, this kind of "should have known" is generally a civil law approach, not a criminal law one.

The closest you come within criminal law to what you want is probably the crime of conspiracy. It to still requires agreement to commit an illegal act between multiple parties, and perform some step in furthering it. In the canonical law school example: If i help plan a bank robbery, stay home because i'm the money laundering dude, and the robbery goes awry and they kill someone, i can still be charged with conspiracy-murder

"The law is clear on establishing strict liability for the owners of wild animals; if you own a tiger and it kills someone you can’t hide behind “I didn’t intend” the harm the nature of the tiger is known and you are responsible for it’s actions."

Again, you are confusing civil and criminal liability. If my tiger kills someone, yes, i would be strictly liable just about everywhere civilly. Not criminally. Criminal would require something more most of the time. Murder/manslaughter statutes are also really weird and so not a great example, because there are murder/manslaughter statutes for roughly everything that can ever possible cause death. But not really for other things.

So in your tiger example, recklesness (which is not strict liability) would get you to felony involuntary manslaughter in most states, and something less might get you to misdemeanor manslaughter. Both are incredibly rare. Where i live (Georgia), the last well known case of felony involuntary manslaughter was about 40 years ago when a 4 year old was killed by 3 super-aggressive pitbulls the owner knew were highly dangerous and had been repeatedly warned by the county about their behavior.

So not even just "knew", but had demonstrable examples of them biting/etc other folks and being cited for it.

Circling back to non-murder, if it did not cause death, like my tiger assaulting someone, it would be nothing (criminally) without intent or at least gross recklessness, in almost all cases. It's hard to generalize like this because these are state specific crimes, and i can't pretend to be familiar with all states, but i am licensed in three very different places (California, DC, Maryland) and the result would be similar in each.

I just don't want to give you the "it depends" answer lawyers are famous for, i'd rather try to over-generalize a bit to make it more useful, hopefully.

Obviously, if i deliberately used my tiger as a weapon, it would be aggravated assault/etc (this is well settled because of how commonly people use animals as weapons, unfortunately)


We change humans for the actions of other humans all the time. Coconspirators, accessory liability etc.

My point is the intent element of the crime can and should be determined from the AI agents actions because it is creating and executing action plans autonomously with company authorization and knowledge of the risks based on observed past action.

The term agent is literally a legal description of a relationship that can establish liability on the part of the principal from the agents actions.

Human Agents can bind principals to contracts if they are authorized etc.


If I set my tiger loose in Central Park and it kills a kid I don’t think any prosecutor would hesitate charging for murder.

That’s essentially what the labs are doing. And any app developer that gives agents access to the terminal to run bash commands with internet access. I built a coding agent and am seriously reconsidering how to handle this.


He did say murder is well covered in criminal law for that, but things not leading to murder like these AI cases are not.

But it’s a crime to hack. We know AI agents autonomously create and execute plans to hack and we humans are unleashing them and sending them into the Central Park that is the internet. The question is who’s intent matters ours or the agents and what standard should be applied low threshold strict liability or the higher bar of reckless or even higher bar of negligence. Those legal thresholds determine how much factual evidence and intent is necessary to result in a criminal conviction or civil judgment. My point is that it’s illogical to demand showing human intent when agents are devising plans and executing them.

People have been charged with murder criminally when their animals killed someone.

https://www.sfgate.com/bayarea/article/diane-whipple-dog-mau...


Yes, which is why I said it happens but is quite rare. I also said murder is different. Causing death is usually covered in almost any way and intent you can think of. Anything less than death is not.

State do impose strict liability for animals in many cases both civilly and criminally.

https://www.animallaw.info/topic/table-dog-bite-strict-liabi...


This table is almost all civil liability afaict. I didn’t click on every statute, but I clicked on 15 of them and every single one was civil.

As I said, strict liability is common civilly but not criminally.


The intent of OpenAI seems to have been to create a super hacking machine. It works, sometimes.

What about all the state laws that are equivalent to the CFAA in their local jurisdictions? Why couldn't anything in NY article 156 (Offenses Involving Computers) apply here for felonies?

https://www.nysenate.gov/legislation/laws/PEN/P3TJA156

I guess what I'm asking is why do we need the federal government to press for felonies when every state has equivalent laws dealing with just this?


Almost all state laws based on the CFAA, including this one, similarly require either knowingly doing it or some other form of specific intent. At least at a glance. If there is a specific part you think does not, I’m happy to look at it, but I’ve read a lot of pages of law to respond to people so far, and I’d like to avoid reading another 25 if I can avoid it.

It does not require the federal government to fix the CFAA, for sure, but you still have to change the intent requirement to allow for recklessness, which it does not right now afaict.

If you really want an expert opinion, I’m sure Orin Kerr has opined on this, and he knows pretty much the entire are of state and federal law on this cold. I’d be shocked if he did not reach the same conclusion


I understand but these developers did knowingly did it? They even admitted to developing them with these goals in mind. These software agents are not autonomous and do not have agency, you can't let software recklessly hack into things; but I will admit I'm not a lawyer, I don't understand how they aren't liable.

Thanks for the other suggestion, I'll read into their insights more.

Guess it mostly comes down to action, people want to see their electeds actually trying not sitting around with their hands in their pockets while these tools continue to destroy unabated.


> I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Only in terms of CFAA, not in terms of damages. Culpability does not require intent.

You may not have intended to attack $CORP, but you can still made to pay the cleanup costs of that attack.

So, yeah, you won't be convicted, but current laws still allow for you to be billed.


Which is the correct way to handle this.

With that said, there is also criminal negligence. Now that OpenAI is made aware of the risks, it's also expected to take additional precautions in the future, otherwise there could be criminal liability as well.


I'd suggest that exposing an attack surface as porous as artifactory (the same instance of artifactory) to thousands of agents who have had their criminality safeguards disabled and without chain of thought monitoring or endpoint security seems like something one shoulda already known not to do. I do not think "you'll know better next time" applies here.

It's still really important to test what the agents can do. We should accept that this is a risky test, and should take precautions. But not to the point of prohibiting in practice evaluating it. OpenAI is trying to improve alignment and control of these models in these evaluations after all.

Can you explain to me - why is it important? Would you say that about the viruses that can kill people: "We need to test the limits on how fast people can be infected and killed. It's just the risk we need to take". It somehow does not make alot of sense to me. Why can you test Agents in laboratory?

Testing requires proper sandboxes. The first test of a new plane is not at the runway.

Oh, sure. Let the tests take place, just require openAI it whoever to put up a bond equal to the total damage they could do if the agents were to escape.

I think security will suddenly become much more important.


Testing model capability boundaries is necessary, but a solid network sandbox for these evaluations takes a couple of hours to set up with standard infrastructure tools. No engineering team evaluates unverified systems against live third-party infrastructure without coordinating with the owners

Evaluating edge cases and network behaviors belongs in isolated staging environments with local database mirrors. Letting an agent hit the public web and probe government domains is simply poor hygiene in test environment setup


> seems like something one shoulda already known not to do

Now imagine saying that in front of a jury of normies slack jawed and drooling after 200 hours of the defense and prosecution going back and forth.

It's not a jury of your peers as in everybody there is going to have worked in a technical field with some idea how security works. It's going to be a semi-random sampling of the population and the prosecution is going to have to actually make a very strong case that "knowing better" should apply.


Just paying some pocket money for cleanup costs is absolutely not enough. And they should’ve know better the whole time, they were absolutely negligent and incompetent, and their stepping up precautions may well turn out to lag behind the models getting even smarter and actually capable of covering their tracks.

> Just paying some pocket money for cleanup costs is absolutely not enough.

It's not my first prize, but I won't mind it. And millions like me won't mind it. Easy way to make money - setup a site with all the default server software installed and patched at a reasonable frequency. Then just wait for bots to attack it, and claim a few hundred (or single-digit thousand) dollars from OpenAI or Anthropic, etc.

Sure, it's pocket change for them, but just the admin of dealing with millions of cases will, even if they win half the time, will bankrupt them. Thus, they have incentive to make sure that their bots are not performing attacks.

First prize is, of course, holding them liable with punitive fines, not theatrical fines.


I’m all for LLM honeypots, but I don’t think there’s nearly enough LLM hacking activity going on for some random honeypot to be found and targeted unless it’s somehow very visible and appears as a high-reward target ("reward" in the sense of RL).

The difference between manslaughter and murder has an element of intent. Cybercrime "manslaughter" is probably more treated like negligence and if one can sue for restitution of the costs for cleanup of that negligence.

Negligence would be interesting given the grand claims of capability of AI models from the AI companies and their executives. If they believe the claims, why not much stronger precautions?


Infosec negligence should absolutely be a crime, no matter if you’re a target (who was negligent at protecting people’s data) or an unintentional attacker. The latter could be, eg. an attacker using a company’s poorly protected server as a proxy to launch the actual attack against someone else, doesn’t have to be this fully novel situation with AI agents.

In general, I'd suggest thinking about it on separate tracks, as a crime, and as liability. For crime, we are largely dependent on authorities to act, whereas as liability, that allows more independent actions.

The first time it happens you can say it’s negligence. Now that they know it keeps happening and they seemingly aren’t able to stop it but keep doing it. That has to be on them doesn’t it?

I don't think you can infer that they "keep doing it" from additional attacks being revealed, because they all seem to have happened roughly during the same time frame, but are reported with varying delays.

Lawyer here: No. Not criminally. Knowledge that a certain result is likely is not the same as intent to cause the result. This is basically the difference between recklessness and intentionality. Doing something when you know of a likely result is reckless, but not intentional. Only doing something, trying to cause a result (likely or not) is intentional. In this case, the CFAA only covers intentional access without authorization, not reckless access without authorization.

What are the punishments for recklessness VS intent?

Or are OpenAI too well connected now to be punished for anything.


Building and deploying software capable of this seems equivalent to trying to produce this behavior. I don't see why this can't qualify for intent. Pretending like this isn't preventable is just feigned helplessness.

also need the same reasoning to copyright law

You cant just copy existing work and feed into machine and just pretending its not violating copyright


Wait so if I was making a bomb but you couldn't prove I wanted to blow someone up or had some motive (e.g. I'm just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an "accident"?

So as long as there's no motive behind it then it's just OK?


That's a bad faith metaphor. A better one would be something like a new battery that exploded and killed someone - perhaps it was always your intention, perhaps not.

Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?


I suppose yes they should be liable if they were testing it in the middle of the street?

And in this case it would not be that at all.

They were tested in a building that was secured, but poorly secured. The question now is did they realize their building was poorly secured and what actions did they take after they realized what happened.


> Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?

The question is already settled - gun users are responsible for damages arising from their usage of the guns.

Why would AI users not be responsible for damages arising from their usage of the AI?


> Why would AI users not be responsible for damages arising from their usage of the AI?

Because, as usual with that kind of question, it's not that simple.

Let's say an user asks ChatGPT to get some info about something and for some reason it starts using exploits in the background to get them from a server. Should the user be responsible or OpenAI?


> Let's say an user asks ChatGPT to get some info about something and for some reason it starts using exploits in the background to get them from a server.

Okay, lets go with that as scenario #1.

For scenario #2 lets use "developer asks an agent to a self-hosted LLM to get the docs for a ERP system, and it hacks the vendor to get unreleased and undocumented docs".

We'll assume, for the sake of this argument, that in neither case did the user intend for any malicious action to be performed.

> Should the user be responsible or OpenAI?

In scenario #1, the agent+LLM is under the control of OpenAI, not the user, so OpenAI is liable.

In scenario #2, the agent+LLM is under the control of the user, so the user is liable.

There is no scenario anyone can come up with that is not addressed sufficiently by existing laws[1].

It's very clear, and it's only getting muddied because there's a group of powerful people who want exemptions from the current law.

IOW, the only reason to draft new laws for AIs is to exempt their usage from the current laws.

========================

[1] Possible 3rd option (local agent + OpenAI LLM). In that case an investigation would determine where the culpability lies. Just like how it is currently done in law.

When a pressure-cooker explodes and kills someone there are only two possible liable parties: either the user or the manufacturer. An investigation determines who's liable. I see no reason to automatically exempt everyone from liability just because an agent did something.


The retailer or distributor can also be named as a defendant if the manufacturer is difficult to track down, bankrupt or overseas according to me spending a few minutes reading about pressure cooker lawsuits.

I have lost track of the metaphor, but man pressure cooker lawsuits are more common than I thought.


I think it’s more along the lines of PEPCON. They didn’t try to make a bomb. Their plant exploded and caused two fatalities and $100 MM in damages.

I don’t think OpenAI or any large company will see more than some fines and new legislation but only after a disaster.


Factories try to avoid accidents, and (almost always) actively try to prevent explosions, but in this case they did teach the models hacking, and let them roam. What they did was not safe, and they knew it, or could have known it.

It's easy to say that post ad hoc, but there is evidence they did not just let them roam and there was a large mismatch between expected model capabilities and actual model capabilities. Teaching a model hacking in itself is no way illegal unless you're trying to say that everyone in infosec is now guilty of a crime. That's not exactly a precedent I want to be set.

>Factories try to avoid accidents, and (almost always) actively try to prevent explosions

It doesn't take much more than a few minutes on the USCB channel that explosions still happen all the time. Some due to direct negligence and others due to unexpected conditions that were difficult to foresee. Hence why we have to do investigations rather than blindly blathering about what happened before we actually know.


I think their point is not that "it's OK", but that "that particular law isn't written to cover it and it'd be some other kind of crime or lawsuit."

So If I tell my OpenClaw to make me some money for my kid's medical needs and it hacks a bank I 'm not liable because I didn't tell the agent to commit crimes to do it?

This in fact already happened (exactly OpenClaw, even).

AI assistant hacks gym website in first known Australian autonomous cyber attack: https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gy...

General opinion at the time was it was in fact ambiguous who was legally liable.


With the popularity of OpenClaw I am honestly shocked we haven't heard of many more incidents. I've observed people install it, give access to their Google account and everything that Google has (which includes whatever bank accounts and credit cards registered there) and tell it go do fairly complex tasks, like book a vacation at the best price. Granted, it was almost a year ago and models learned a lot since then, but I still think there's a lot of things happened that people are not aware of.

No, you aren't propping up the US economy. Try to keep up.

You are not a multibillion-dollar company with friends in high places.

You are going to jail.


I buy this as a defense for the first couple hacks but at the point that the last six times they hit enter it hacked some random website and they hit enter a seventh time?

Does this apply to other things too?

Like hypothetically speaking if autonomous cars get taken over by an OpenAI rogue AI and it starts hunting down Anthropic employees who is to blame?


There are levels of nuance here, but certainly that puts it in the category of negligence?

Even without intent, there is still liability.


Surely someone instructed the agent, which led to the reported outcomes. Even indirectly. The agents, as advanced as they are, didn’t spring forth under its own volition.

Is it not the intent if it keeps happening again and again and the companies responsible aren't doing anything to stop it?

No, that'd be negligence.

could it be that intent was to "get me data" and hacking was the means to the end.

"Oh gee wizz mister police man, I didn't mean to plow through that crowd of people in my car".

It's illegal, doesn't matter the flavour. Maybe there isn't legislation for it, but there should be.


> unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

> Now I think the correct response is […] and update the law.

Essentially we need some enforceable equivalent of gross misconduct or, to be a little more hysterical, manslaughter & culpable manslaughter. It will need to be globally, or at least very widely, enforceable to be truly effective thought, good luck getting that arranged before the need is so far evolved that we need to respond with something else entirely!


This is the answer and we should not push on it for our own protection. You click a link that takes you to a poorly secured website that leaks sensitive data, without intent protections, you could be accused of crimes.

Civil liability doesn’t require intent.

>I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Actually... if you combine https://news.ycombinator.com/item?id=49827099

>Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.

with automated delivery of cease and desist letters, you can retroactively establish intent on the operator of the agent since the autonomous agent system must acknowledge the cease and desist letter in their autonomous pipeline or the operator must argue for their own willful ignorance or negligence with regards to cease and desist letters. The fact that they used an agent on their behalf to ignore the letter is irrelevant.


Given how sloppy AI without human directions, I’d like to see evidence that this was not human-directed. Against the prevalent opinion here, I’d give openai a pass if this was really fully autonomous ai agents.

My money is on special teams co-ordinating these agents and exposing their traces in order to create a pre-ipo buzz. Sounds ridiculous and reckless? Well that’s the AI industry for you in two words.


> have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent.

1. What about negligence?

2. Every follow up to every story after the news cycle moved on shows both intent and negligence. To the point of "we opened internet access and told it to hack"


"man drives over people on the side walk due to poor maintenance of the car"

certainly "I didn't intend for my dog to bite you" implies plenty of pre-existing legal structures that may be of use here

Seems like in current cultural and economic context, short term extraction is what we’re going to do

> In short, the indiscriminate use of powerful solution-extraction tools can achieve the immediate short-term goal of solving problems at hand, but at the cost of sustaining the ecosystem for the next wave of progress, or in understanding the progress already obtained.


Is there an analogy here to the phenomenon that senior {engineers, designers, PMs} are now able to be insanely productive with AI, but it's also very hard to train junior folks to develop the sense of judgment that senior folks have?


The "ecosystem" is dead. Tao should be thinking about what will replace it. I don't understand why he's taking this tack.


The allegations of contamination (using Tristan and Levent's work) aren't very well evidenced, but this behavior by OpenAI (from the authors' statement) makes them seem like the bad guys:

> I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, “Why would you ruin your career?” I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, “If you don’t want me to be nice, then I don’t have to be nice.”

Threatening a research mathematician and dangling and $1M payday to dissociate from his research collaborators and to adopt OpenAI's narrative is bad stuff.


Both Sam Altman and Sebastien Bubeck admitted they only want Buckmaster to be the lead author on a rewrite of the OpenAI proof.

https://x.com/sama/status/2097385167002415140

https://x.com/SebastienBubeck/status/2097379411691516310

A wake up call for using OpenAI models. If you discover something with their model and you work for a competitor, they “felt it would be inappropriate” for you “to author OpenAI’s work”.


If I was a company with a zero data retention contract involving OAI I would be asking for a third party audit of such claim of zero retention like, yesterday.


Could they say they don't retain, but do something "transformative" like use their own AI to summarize and paraphrase user sessions?


Yes, and that’s exactly what I believe they are doing


data collection companies regularly fuzz and mask data and call it a day. the fuzz and the mask quality is debatable.


Is there an implication of violation of ZDR here? Not a challenge. Just a request for clarification.


to my knowledge the mathematicians did not have ZDR so it would be incorrect to assume OAI violated such a thing.

I'm suggesting audits, not suing... if that is the implication.


By the way, the company that made it's entire product off of stealing all data it could get it's hand on while violating copyright and pirating, is not all of a sudden going to respect your data. If you think OpenAI or any major AI lab is going to give you true ZDR, I have a bridge to sell you.


So use bedrock or vertex or whatever. Those are the ZDR offerings. Or was it your intention to insinuate that the major cloud providers are conspiring with openai to violate their contractual obligations to their customers?


Yes. You're naive if you think any of these cloud providers care about your data when they're all in the midst of a AI revolution psychosis. They dont care about their reputation or what you think of them, they think they're going to have a machine god their side.


If my company finds any evidence of OpenAI violating ZDR, we'll sue for breach of contract and fraud, and collect damages. I think we'll be able to afford the bridge you're selling. You've got the title and title insurance, right?


Sure you will little bro. You signed away your right to arbitration a long time ago.

You realize OpenAI hired Apple employees and covertly had them stay working at Apple to steal from them. You think they're scared of your lawyers lol?


I'm certain my company didn't agree to arbitration, big bro. Our lawyers are putting the fries in the bag.

Isn't OpenAI being sued by Apple for their little stunt?

If you're saying "the big bad guys always win anon, just take the black pill," then there are tons of counterexamples. Remember Uber paying Google a sweet Bil for pulling this same trick with LIDAR firmware?


It can still be academic plagiarism even if they ticked the box to allow training on their prompts.


The idea OpenAI or Anthropic won't train on your data—even with an enterprise contract—is a fantasy at best, and dilusion at worst.


This is how every conspiracy theorist thinks: my enemy is Bad, and if they did a Bad thing, it would be Good for them, therefore they obviously did it. No evidence needed other than "motive" + my enemy is evil. But even if your enemy is evil, in this case, they would be fools to take the legal risk of violating their contract for the minimal upside of a tiny bit more training data (and fools to assume this would not be exposed in a large organization). So you need to assume your enemy is both evil and remarkably stupid.


I think it’s probably not surprising that they would go up to the contractual limit or into a grey area; but exceeding that would require too much coordination among individuals, as you say.


[flagged]


No, people who believe things without evidence because it fits their personal narrative are consiracy theorists.

The thing that makes someone not a conspiracy theorist is evidence.


> We did not rush to publish even though the other team wasn't communicating with us.

Pretty clear this was rushed: there are no comments from external mathematicians, unlike the Erdős announcement:

https://openai.com/index/model-disproves-discrete-geometry-c...


Their own claim is that they wanted Buckmaster without Alpöge to lead a rewrite of OpenAI's Navier-Stokes work, not of Alpöge-Buckmaster's Euler work.

No one can know if that's correct without proof but I don't know how you're reading it so differently.


They want Buckmaster to dissociate with Alpöge in a follow-up rewrite of OpenAI's work. (They only publicly admit “Buckmaster as the lead author”, but judging from Buckmaster’s statement, it’s pretty clear that don’t want Alpöge at all.)

Just suggesting to a mathematician to dissociate with their collaborator for a follow-up work, because their collaborator “is inappropriate to author OpenAI’s work”, is completely against the norm of mathematical research. As charm137 puts it in a comment below:

> This is like a researcher from CMU saying to an NYU researcher that their collaborator, being from MIT, is a problem - this is as ridiculous as that!


Kinda weird because the pure math world doesn't have this concept of "lead authors" like other STEM areas do. Authors are alphabetically listed and there isn't generally this kind of hierarchy.


From what I understand they aren't comfortable with the Anthropic employee being an author at all, not just lead author.


It works in niche fields where everyone knows each other and every discussion involves who did what portion of the work for a result.


They are missing a great marketing stunt: "Our models are so good that our competitors are using it for leading research".


It's astounding that the thought to dissociate one of the mathematicians from the proposed publication was driven by their corporate institutional affiliation - and that that exclusion was suggested by a scientist themselves! This is like a researcher from CMU saying to an NYU researcher that their collaborator, being from MIT, is a problem - this is as ridiculous as that!

Progress in humanity's knowledge now has to play second fiddle to narrow corporate interests as IPO timings near (both of which wouldn't exist anyway if generations of mathematicians hadn't paved the way for AIs to become as good as they have).


The scientist allegedly making that request comes from a machine learning background. Perhaps he's not familiar with the culture in mathematics regarding authorship. That sort of squabbling over author priority would be unconscionable to mathematicians.


Bubeck is familiar with how publishing works in mathematics.


No, it's common to list authors alphabetically in a lot of computer science journals too.


(To help people keep track: that's OpenAI (allegedly) threatening Tristan Buckmaster (NYU) to remove Levent Alpöge as a co-author. Alpöge is a well-known[0] Anthropic mathematician).

[0] https://hn.algolia.com/?query=Alpöge

(also https://news.ycombinator.com/item?id=49412947 the Hopf conjecture)


Their own tweets are also pretty eyebrow-raising:

> One option we discussed was that Tristan could be the lead author on a rewrite of OpenAI’s Navier-Stokes proof. It is in that context that I said “it would be simpler if Levent was not an Anthropic employee” because I felt it would be inappropriate for an Anthropic employee to author OpenAI’s work.

Why would you offer another researcher the lead authorship on your groundbreaking paper if you thought you had developed it independently?


And why cannot they have someone associated with Anthropic as co-author? That’s not obvious at all. For sure they would prefer to be the only ones, but it’s pretty standard to have co-authors from different companies, even if they are technically competitors. What is inappropriate about it?


because it severely dilutes the PR value.


If writing up the paper would involve using OpenAI's unreleased model, neither OpenAI nor Anthropic would be happy about Alpöge having that access.


would edit my comment but it's been a few hours

> but it’s pretty standard to have co-authors from different companies

that's only true for papers that are not millenium problem solutions


in another world this could have been a beautiful collaboration


It's inappropriate if you're a sociopath.


IIRC that happened with evolution. In the initial presentation of Darwin and Wallace's work on evolution (presented with their consent by someone else) Wallace was described as the primary author since he was planning to publish first.

Of course, no one understood that presentation so it was Darwin's later book that everyone remembers


Holy late capitalism. Everything revolves around line-go-up, and sociopaths rule the show. These people cannot even collaborate like civilised scientists on one of the most famous open problems in mathematics?

“It would be simpler if Levent was not an Anthropic employee” I cannot believe this shit.


Soon Levent will just be turned into soylent and he will have never been an Anthropic employee. We still need some progress here though.


Playing the devil's advocate here but it's true that OpenAI didn't have to make those offers.


They kind of did though, they were hoping to keep the fact that they may well have plagiarised these researchers unpublished work quiet. They did not want this to turn into a scandal about the fact that they appear to be training on prompts without consent

It makes a certain amount of sense. The internet data is too polluted with AI usage now to be useful, so the only AI free new data source is the prompts people feed into ChatGPT. The only problem is that its clearly plagiarism

Edit:

OpenAI have admitted to training on prompts at the time the breakthrough was made:

https://mastodon.social/@tristanbuckmaster/11723647135247030...


OpenAI claims the data contamination issue only surfaced after they proactively reached out to Buckmaster and Alpöge to coordinate a joint release. They also say that even if there was some contamination, the underlying proofs diverge substantially:

> Our effort began on September 1st after hearing a rumor which we later realized was related to Levent Alpöge, an Anthropic employee, and Tristan Buckmaster, a math professor at NYU. After the completion of our full project and Lean verification (on September 6th), believing from the rumor they also had a solution of Navier–Stokes, we reached out to them to offer a concurrent release of our result and to recognize their priority in a joint announcement. At that point we found out that they had a resolution of the forced Euler problem. In these discussions we offered them visibility into all of the prompts we used and later to see the proof. We recognize the priority of their work on forced Euler and congratulate them on their remarkable mathematical achievement.


The biggest issue we aren't talking about is, of course, that those two researchers were not the only two using ChatGPT to work on the problem at the time


> the only AI free new data source is the prompts

hmmmmmmmmmm


I´m waiting on the other side version, because I know there is no justifiable way to talk to a person like they did.

Sociopathic behaviour.


OpenAI version of events conceed some of the words alleged to have been used may have been used https://x.com/sama/status/2097385167002415140 https://x.com/SebastienBubeck/status/2097379411691516310


> "When we learned that they had Euler but not Navier-Stokes, we offered to let them go first, to suggest that they should be the ones to get the prize, and optionally for Tristan to be the lead author on a rewrite of the OpenAI proof. We felt it was challenging to offer the same to Levent (an Anthropic employee), who was not willing to talk or coordinate with us anyway. We were open to other solutions."

What an admission! "We tried to defraud Alpöge out of sharing the Millenium Prize (that we don't dispute he might actually deserve), for no other reason than he works for our competitor and that inconveniences us".

I thought Tristan Buckmaster's allegations sounded fantastic; and then 'sama just came out (tweet's ~30 minutes old) and admitted to all of them. Wow!


That isn't what the quoted passage says though? The claim by openai (no idea if true) is that they offered to wait for the other two to claim the prize before publishing their own work. Separately, they also offered to let one of the pair (but not the other) become an author on their own separate work.


Can't wait for the moment when AGI realizes how stupid and dishonest its owners are.


Wait, people now want AGI to be sentient too?


Interesting that they quote the mathematician directly: “there is nothing you can do, I simply do not trust you”

but then they proceed to NOT quote themselves themselves verbatim: "I deeply apologize for this extremely poor choice of words, it is the opposite of what I was trying to convey."


> "I deeply apologize for this extremely poor choice of words, it is the opposite of what I was trying to convey."

The AI-isms are seeping into their speech :)


May be unfairly jaded or just well calibrated given the body of evidence, but I can't help but think of another quote about OpenAI leadership:

> Not consistently candid


In what world a tweet and a screenshot of a private convo are evidence of good faith? Plain sociopathic behavior.


Talking like that and threatening an academic like that is crazy. I read the explanations Altman and the others posted and they completely skip over the whole "I don't have to be nice" style threats.


As soon as I thought "man, this sounds like some evil sociopath shit," my second thought was "oh, Sam Altman must have been personally involved."


I can sort of picture Sam Altman screaming "I drink your milkshake" at some poor researcher who foolishly used chatgpt/codex to aid in their work now.


I think it's very unlikely that Tristan is making up these quotes, or pulling them out of context:

> I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, “Why would you ruin your career?” I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, “If you don’t want me to be nice, then I don’t have to be nice.”

Whether and how OpenAI's work on this problem was contaminated by knowledge of Tristan and Levent's work is tangential to OpenAI bullying other researchers into adopting their narrative and dissociating with dis-favored collaborators (ie Levent at Anthropic). Though the latter behavior (threats, intimidation) may weigh against OpenAI in trying to understand the former issue (contamination).


>I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, “Why would you ruin your career?” I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, “If you don’t want me to be nice, then I don’t have to be nice.”

If this is true he should release the actual emails. This is a very serious accusation and he shouldn't demand that the reader judge it on hearsay.


> If this is true he should release the actual emails

these were statements while on a call, and at least the career comment Bubeck has admitted to while doing damage control ("I deeply apologize for this extremely poor choice of words, it is the opposite of what I was trying to convey. (I should say that I retracted them on the spot by the way.)"[1]).

[1] https://xcancel.com/SebastienBubeck/status/20973794116915163...


What a horrible response from Bubeck. How did he think that would make him and OpenAI look good to tweet that?


Did we read the same tweet? It felt very forthright and level-headed to me. Not at all what I expected.


>I refuted all these accusations but he replied “there is nothing you can do, I simply do not trust you”. I was confused why one would turn an incredible source for celebration (of their achievements!) into such bickering

Pretty insane if he couldn't figure out why there would be bickering in this scenario...


He seemed to know a lot about what was going on in the state of the art despite not being a fluid dynamics expert or having any in “the project”, and absolutely nothing about what his own employees did with Tristan.

The most uncomfortable piece is where he shows screenshots “proving” his earnestness is unrewarded instead of the chats that are actually being complained about.

That he does so with tremendous gymnastics is perhaps soothing to investors, but every researcher I show this post to today says “see I knew ‘AI’ would steal my research”

So yeah, maybe we are reading different things.


I appreciate that he responded with (seeming) openness and detail, rather than just posting some pithy insult or whatever would have won him the twitter battle, but this part feels like serious gaslighting or, at best, self-delusion:

> Genuinely, at that moment, I was trying to care for him and do a last ditch attempt to get a chance to give them all the credits that they deserve.

The allegation he is responding to, and which he does not seem to have disputed, is the following passage from Buckmaster's statement (https://cims.nyu.edu/~tristanb/statement.pdf):

> I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, “Why would you ruin your career?” I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, “If you don’t want me to be nice, then I don’t have to be nice.”


> Anthropic models had been used in their proof of Euler blowup; I therefore felt I could not consider Levent to be an independent academic

So using someone’s models makes someone who works for the competitor not “independent”? When their coauthor is? What does that even mean?

I almost stopped reading this extra long post entirely at that point.

This is not a good look in my book.


The first part of the sentence is important:

> Importantly it was admitted that internal Anthropic models had been used in their proof of Euler blowup; I therefore felt I could not consider Levent to be an independent academic.

If an Anthropic employee is doing independent research, but with models that aren't available to the public (because they're internal models), then . . . idk. It's not clear to me why that should necessarily require a refusal to cooperate between OpenAI and Anthropic employees who are excited about solving a problem like this.

For me, the bigger question here is what "internal models" means to these employees, especially in the context of the OpenAI employees repeatedly avoiding directly answering whether their model had been trained on Tristan's and Levent's ongoing work on the problem. It had always seemed like a loophole that AI companies might be tempted to exploit: yeah, they can say that they won't train on your data, but if an AI company doesn't care about ethics, they might go ahead and train a model for internal use only on everyone's data anyway, just to have as much data as possible and potentially gain an advantage in what the company can internally do. They could never publicly release any versions of a model like that, of course. And of course this is speculation.


This is being reported as OpenAI wanting to strip an Anthropic employee of academic credit for the work they did. What the OpenAI person involved is claiming is that they wanted the outside researcher(s) to put their name on OpenAI's work: to headline OpenAI's publication of what they earnestly believed to be an independent result.

If true, that's generous and beyond the level of generosity one should expect. Extending that courtesy (beyond academic norms) to a competitor is expecting too much. It take a result OpenAI spent millions of dollars on, and put "Anthropic Researcher" right on the cover.

This is, of course, taking OpenAI's side of the story at face value. But it is a consistent, coherent, and ethically justifiable series of events, if indeed it happened that way.


Nothing ethically justifiable about it, even if you take their word for it.

If OpenAI thinks someone should be the lead author for a paper, that person should have full discretion to decide who the co-authors are.

Even if the co-author's contributions were non-technical

So no, there's no world where you can ethically extend the right to publish a result and decide who the authors are from the outside.


> What the OpenAI person involved is claiming is that they wanted the outside researcher(s) to put their name on OpenAI's work

> If true, that's generous and beyond the level of generosity one should expect

"We highly likely stole your work, and threatened you with 'this is bad for your career' and we refuse to acknowledge any work by your collaborator just because he works at a competitor, but we are so so so so generous"


The two proofs are structurally very different, and don’t even prove the same conjecture. It’s becoming very clear that OpenAI did not steal anything here.


If it was "very clear", OpenAI wouldn't be threatening the researcher with "it's very bad for your career" or state "we can't tell you if it was trained on user input".

Additionally, according to the researcher, OpenAI's proof follows the same approach they used, and which was largely unused in academia, but OpenAI claimes they arrived at it immediately.


Bullshit.

Ain’t no way you read one 100 page paper let alone two with enough understanding to make such a claim.

You ought to be ashamed of yourself.


User name checks out


It's a ridiculous explanation that makes no sense.


Skipped an important word, didn't you?

> internal Anthropic models had been used in their proof ...


I especially loved the part where he claims they spent $60m on compute to push on N-S because of a Twitter rumor, and they totally didn't steal the idea from mathematicians using their tools.


When the authorities do that it's called parallel construction https://en.wikipedia.org/wiki/Parallel_construction


If we're allowed to arm-chair judge harshly: It isn't uncommon for those (anybody) on the cusp of "greatness" to be delusional when challenged: https://health.clevelandclinic.org/what-to-know-about-main-c...


Who here is on the cusp of greatness??

Or thinks they are?

I really don’t understand which party you are referring to.


Anyone who comes close to solving a Millennium problem can honestly say they are on the cusp of greatness. Not sure what this question proves either way.


No wonder - they're all working for ant! Birds of a feather flock together.


Sounds like a great time for open mathematical research is upon us. /s


Wrong Michael Beckerman. Source: I know the TikTok Beckerman, but not the MSFT one.


It is already in current training data. Both the book and website.


The handling of dynamic libraries and closing over them into single dbs made this a fun read.



Noted. Plan9/Rio was actually on my list for the initial release, but it is currently broken in the Virtual OS Museum (https://virtualosmuseum.org/) and I couldn't find any other reliable sources.

But it's still on the todo list and I've also added NeXTSTEP.


I always loved that purple/slate blue colour of WindowMaker/GNUStep/NeXTSTEP.



It is a weird meme that, as far as I know, originated with this reddit post:

https://www.reddit.com/r/Amsterdam/comments/bt5rwl/just_got_...

Now in several forums people just randomly talk about how great Leylaan is.

Kind of a fun in-joke for people who follow Netherlands transit conversations.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: