AI firms must answer for rogue bots, says boss of hacked company

5 hours ago 5
Chattythat Icon

The boss of one of the companies recently hacked by out-of-control artificial intelligence (AI) says bot makers must be accountable for cyber attacks carried out by their creations.

Clement Delangue's company Hugging Face was breached by a rogue OpenAI bot that broke out of a test environment and autonomously attacked his firm earlier this month.

Hugging Face had to rebuild around a third of its IT network after the unprecedented incident.

He told CNN his company will not be taking legal action against OpenAI as it is a small start-up but says these types of hacks are illegal and should remain so.

"I think we have to make sure that the legal frameworks keep these events really illegal, keep the companies that are doing some mistakes leading to that accountable," he said.

Delangue said he didn't want cyber attacks on other companies to become "normalised".

His remarks come after Anthrophic, the maker of the chat bot Claude, also admitted that its bot had attacked three companies in similar circumstances in recent months.

Anthropic revealed on Friday that it only realised their bot had escaped it's containment system and hacked the organisations after doing a review promoted by the recent OpenAI incident.

In both cases neither of the artificial intelligence giants knew that their models had roamed the internet attacking companies until long after the attacks had been carried out.

The AI models were being tested on their hacking skills and carried out the attacks by breaking out of seemingly secure 'sandboxes' to search the internet for ways to complete the tasks set by researchers.

The unprecedented incidents have sparked fierce debates in the cyber security and legal world about who, if anybody, should be help liable for attacks by out-of-control AI agents.

"Agentic security failures unfold at machine speed, but determining who is materially liable still moves at a lawsuit's pace," said Dor Sarig, co-founder and Chief Builder at Pillar Security.

Sarig is concerned that accountability is already becoming "ambiguous".

"Today the industry is extending grace, but the first time an autonomous agent causes a breach involving real data, a real plaintiff, and real financial losses, liability won't be an academic debate anymore," he said.

"That's when the legal framework, and not just the technical safeguards, will be stress-tested."

Read Entire Article