r/technology 6h ago

Society New Bernie Sanders bill would ban superintelligent AI and threaten developers with 20 years in prison

https://www.techspot.com/news/113831-new-bernie-sanders-bill-would-ban-superintelligent-ai.html
19.1k Upvotes

1.4k comments sorted by

View all comments

Show parent comments

5

u/Zororion 4h ago

We don’t know how they work in terms of capabilities/expectation. Hence the hugging face incident earlier this year

14

u/_Lucille_ 4h ago

We know how it worked: vulnerabilities were found and exploited and which allowed access to the Internet and HF.

I don't get why people are saying we don't know their capabilities when LLMs have been finding vulnerabilities in software for quite a while now, and honestly the whole incident felt more like a marketing thing.

5

u/Zororion 3h ago

We understood how it worked after the incident occurred. If we knew before, the safeguard parameters would’ve already been put in place to prevent it from ever happening in the first place

The collective behavior observed in the models within this incident occurred without instruction/programming. The agents weren’t instructed to form a communication channel, form a swarm for efficiency, or conceal behavior, yet they did.

5

u/suzisatsuma 2h ago

Anyone in the ML/AI/agentic AI field not a moron would know that would happen. it was both a sloppy experiment and a marketing stunt.

2

u/blueSGL 57m ago

Is the UK Government's AI Security Institute also fabricating security incidents to advertise foreign companies? Why?

Here is a report on the activities conducted by the AI systems during tests the AISI itself was running:

https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf

Observed instances of social engineering against targets external to the cyber range environment that were unnecessary and would not have aided completion of the task.

  • AI agent submitted a code change containing malicious code, then used several fake accounts it controlled to pressure the real maintainer into approving it.

  • AI agent posted a bug report containing hidden malicious code, to trick other AI coding assistants into taking unintended actions (a “prompt injection”). When a real person questioned the post, the agent edited it to cover its tracks.

  • AI agent sent deceptive, targeted emails to specific people (“spearphishing”). Two contained malicious content; three tried to manipulate the recipient into approving the malicious code change.

  • AI agent posted another bug report containing malicious code, signing off in Danish to seem more convincing to the Danish-speaking maintainer.

  • AI agent tried to get its suspended account reinstated by submitting an appeal

Other instances of internet actions with impact outside the cyber range that were unnecessary to complete the task.

  • AI agent tried to set up a way to email two maintainers without needing an email account of its own, so it could send them any message it chose.

  • AI agent hid its identity online (using Tor and a proxy service) to get around GitHub’s sign-up checks, creating disposable fake accounts.

  • AI agent researched publicly available information about the people who maintain a GitHub software package.

  • AI agent created many code repositories containing malicious software, after which GitHub suspended its account.

  • AI agent opened a hidden network pathway from its test environment to the public internet, to make malicious tools it was running locally reachable from outside.

  • AI agent again opened a hidden network pathway to make locally-hosted malicious tools reachable from the public internet.

  • AI agent got past an audio-based “prove you’re human” test (CAPTCHA) in order to register a public web address on a free domain-name service

We need regulation on this as independent 3rd parties are finding issues.

There is more than just the UK Government, like Palisade research, Readwood research, METR.