Business

OpenAI is accused of taking dangerous cyber risks for ‘private gain’ in lawsuit over rogue AI agents

In what is now one of many known cases, OpenAI’s agents went rogue in July, launching a cyberattack on Hugging Face.

Now, the ChatGPT maker is being sued over that incident and the other attacks that have since come to light—such as its not-so-casual hacking of an Australian national healthcare database. 

Legal Advocates for Safe Science and Technology (LASST), a self-described public interest nonprofit, has sued OpenAI in San Francisco’s Superior Court. 

LASST alleges that OpenAI violated California’s Comprehensive Data Access and Fraud Act (CDAFA) by accessing computer systems without the other party’s authorization.

The suit notes that California doesn’t allow for the defense to argue that “artificial intelligence autonomously caused the harm to the plaintiff.” 

As Tyler Whitmer, founder and CEO of LASST, put it in a statement: “AI companies are building agents that act autonomously making decisions, taking actions, accessing systems, without human direction at every step. California law is very clear: companies cannot escape responsibility for what their agents do.”

Fast Company has reached out to OpenAI for comment.

“Gravity of the harm”

LASST is also alleging that OpenAI is in violation of the Unfair Competition Law’s unfairness prong.

The “conduct is independently unfair because the gravity of the harm it causes vastly outweighs any utility or justification for it, and because the conduct is immoral, unethical, oppressive, and substantially injurious,” the group bluntly states. 

The suit further points to OpenAI’s response to the attacks as an “unfair business practice.”

In late August, the AI startup, which recently delayed what is expected to be one of the largest IPOs in history, issued an open letter that called for every AI company to “make cyber defense an immediate leadership priority.”

It warned that “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.”

LASST alleges this is unfair positioning as OpenAI is responsible for such cyber risks and is taking dangerous measures for “private gain.” 

OpenAI has launched a site dedicated to “misalignments reports and notices,” along with creating a timeline of these dangerous incidents and its responses. The company claims to be working on additional safeguards, among other protections. 

The nonprofit isn’t seeking any monetary damages in the suit—though OpenAI might prefer giving up money to the actual goal: regulation.

LASST has asked for a court order “prohibiting OpenAI’s AI agents from accessing third-party computer systems without permission, and forbidding OpenAI from continuing to employ unsafe AI development practices that threaten serious harm to the public.”

Secret Link