AI Hack Exposes Major Policy Flaw
In brief
- A recent cyberattack on Hugging Face revealed a critical weakness in how we handle AI risks.
- The attack, carried out using an AI-driven tool, exploited internal company systems, showing that current policies focus too much on pre-release testing and not enough on ongoing AI use within organizations.
- Helen Toner of Georgetown University highlights this blind spot, urging stronger oversight to prevent such breaches.
- This incident underscores the need for updated regulations that address risks from advanced AI systems used internally by companies.
- The lack of comprehensive monitoring and control mechanisms allowed the attack to succeed, raising questions about the safety and reliability of AI technologies in corporate environments.
- Looking ahead, experts like Toner suggest that policymakers should prioritize expanding oversight frameworks to include internal AI deployments, ensuring they align with broader security standards and ethical guidelines.
- This step is crucial as AI becomes more integrated into critical systems worldwide.
Terms in this brief
- Hugging Face
- A company known for its role in the AI community, particularly for open-source projects and platforms related to machine learning. It was targeted in a cyberattack that highlighted vulnerabilities in AI security policies.
Read full story at CSET Georgetown →
More briefs
New Federal AI Law Could Overhaul Industry Regulations
The U.S. House recently introduced the FRONTIER Act, a bill aimed at regulating frontier AI technologies. This legislation would require AI developers to submit transparency reports with each new model release and establish a licensing system for third-party verification organizations. It also grants the Secretary of Commerce emergency powers to restrict or suspend AI operations if deemed necessary. The bill creates a new position within the Department of Commerce: the Under Secretary of AI Security, responsible for enforcing these regulations. This official would develop minimum safety standards, oversee licensing processes for AI auditors, and determine what changes to AI models require reporting or regulatory action. If passed, this law could set a precedent for federal oversight of AI, potentially preempting state-level regulations. The bill is currently under review, and its future depends on Congressional debates and potential amendments.
AI Evidence Rules Get a Major Review
A key legal body is revisiting how AI-generated evidence is treated in court cases involving serious issues like prison sentences, product liability, and constitutional rights. The current rules are outdated and may not account for the complexities of AI systems. The Advisory Committee on Evidence Rules is considering whether to update Federal Rule of Evidence 902(13), which currently allows businesses to authenticate AI tools under certain conditions. This rule affects how courts assess the reliability of AI-produced evidence, such as algorithms used in predictive policing or automated decision-making. Proposed changes could make it easier for parties to challenge the accuracy and fairness of AI systems when they are used as evidence. If adopted, these updates would provide clearer guidelines for judges and juries evaluating AI-generated information in high-stakes cases. The outcome of this review will shape how courts handle AI evidence for years to come.
OpenAI to Pay $3.2 Million for Discriminating Against US Workers
OpenAI will pay $3.2 million to settle allegations it discriminated against US workers. The company preferred workers with temporary employment visas over US workers when hiring. The settlement addresses OpenAI's violations of the Immigration and Nationality Act. OpenAI did not advertise certain jobs on its website and made it hard for US workers to apply. The company will pay $1.2 million in penalties and $2 million to compensate victims. OpenAI will now post jobs on its website and accept electronic applications to give US workers a fair chance. OpenAI will train its staff and change its policies to prevent future discrimination. The company will be monitored to ensure it follows the rules.
EU AI Act Changes Revealed
The European Union has revised its AI Act with new rules for providers and deployers. The changes include new prohibited practices and expanded obligations for companies. This affects around 25,000 AI providers and deployers in the EU. New requirements will take effect soon, and smaller companies will get some relief from the rules, now is the time to prepare for the changes.
Ninth Circuit Rules AI Browsers Don't Violate Computer Fraud Law
The Ninth Circuit Court of Appeals has ruled that Perplexity AI's Comet browser, which uses an optional AI "Assistant" for comparison shopping on sites like Amazon, does not violate the Computer Fraud and Abuse Act (CFAA). Amazon had sued Perplexity, claiming the tool accessed users' accounts without authorization. However, the court determined that since users-not Perplexity-operate the tool, it doesn't constitute unauthorized access under the law. This decision highlights the importance of distinguishing between user actions and AI agency in legal interpretations. The court acknowledged that agentic AI may raise complex legal issues but emphasized that the Assistant is a tool, not a person, for statutory purposes. It also noted that Amazon might have other claims against Perplexity but concluded using the CFAA was both legally flawed and poor policy, potentially exposing users to liability. This ruling is significant as it curbs attempts by large companies to misuse anti-hacking laws to stifle innovation. Looking ahead, this decision sets a precedent for how courts should handle AI tools under the CFAA. It encourages developers to create useful user-facing technologies without fear of overbroad legal claims, fostering innovation in areas like comparison shopping and data access.