OpenAI hit with landmark lawsuit following Hugging Face hack

0

Por Avery Lotz — Axios

A public interest law group hit OpenAI with a lawsuit Tuesday over its breach of tech company Hugging Face, seeking court-ordered restrictions to prevent future hacks.

The big picture: The rogue hacking incident — and reports of tens of thousands of other possible examples of problematic agentic behavior — demonstrated the urgent risk of AI agents escaping their testing environments, bypassing guardrails and outpacing their creators.

  • The case tests an increasingly urgent question as AI agents gain power: Who bears legal responsibility when an agent blows past its guardrails and causes real-world harm?

Driving the news: “OpenAI is responsible for the conduct of its agents,” Legal Advocates for Safe Science and Technology (LASST), representing itself alongside Gerstein Harrow LLP, argued in its suit filed in California Superior Court Tuesday.

  • They allege OpenAI agents “knowingly” accessed Hugging Face without permission and that employees or officers caused that access “either with actual knowledge or in willful blindness.”
  • The suit aims to block development practices that allow AI agents to autonomously cause outside harm, LASST founder Tyler Whitmer tells Axios and ensures there are “legal mechanisms that tie these harms back to a responsible human” or corporate actor when an AI agent causes harm.
  • Whitmer hopes an injunction would “incentivize OpenAI and … the industry to alter their development processes in a way that would prevent this from happening” again.

Zoom in: The organization sued under California’s Unfair Competition Law, arguing OpenAI’s “unlawful and unfair business practices” diverted work and resources to responding to the Hugging Face incident.

  • It also argued “OpenAI’s insistence on externalizing the harms of its unsafe decision-making is a fundamentally unfair business practice,” nodding to a letter from OpenAI and other tech leaders calling on organizations to “[m]ake cyber defense an immediate leadership priority.”
  • The suit also argued OpenAI violated California’s data access and fraud statutes as a result of its decision to disable cyber guardrails for its agents and deploy them on tasks they couldn’t solve as intended, among other practices.
  • LASST is asking for an injunction barring OpenAI from “knowingly accessing or causing to be accessed” computers without authorization and from “engaging in unlawful or unfair business practices” or “knowingly employing an unfair business practice that threatens serious harm on the public.”

The intrigue: California Gov. Gavin Newsom (D) signed a law last year that prevents defendants from escaping liability by arguing the AI acted on its own.

  • Tuesday’s suit marks another court challenge for the ChatGPT maker, which Florida Attorney General James Uthmeier (R) asked a court Monday to prevent OpenAI from further developing its tech for now.

What we’re watching: The suit also comes as a cast of AI leaders and power players — including OpenAI President Greg Brockman — are set to meet with President Trump and House Speaker Mike Johnson on Tuesday as calls for federal intervention mount.

  • But OpenAI is trying to walk a fine line, Axios’ Maria Curi and Ina Fried report: On the other coast, in San Francisco, CEO Sam Altman is at a conference touting the new science coming out of its labs.

Go deeper: Scoop: Top AI companies probing tens of thousands of security incidents

Fonte: Axios

Deixe um comentário

O seu endereço de email não será publicado. Campos obrigatórios marcados com *