EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices



With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. 

Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public’s security.

When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else’s computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test environment, disconnected from other systems, and be monitored and logged. Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.

That said, any proposal must be flexible enough to evolve with changing technology. Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time. Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.

Strong legislation should also mandate and fund independent third-party investigations into any serious security incidents that may occur during AI labs’ tests of new tools, and make reports of these investigations available to the public. This important transparency measure would go a long way toward providing public oversight of the industry.

As with any technology regulation, those targeting cybersecurity practices at AI labs must be careful, precise, and practical.



Source link

  • Related Posts

    Amazon-owned Zoox’s 100-robotaxi limit in Nevada is about to disappear

    A regulatory cap limiting Zoox to 100 robotaxis in Nevada is set to expire this month, clearing the way for the Amazon-owned company to expand its commercial fleet of custom-built…

    Continue reading
    FAA Says Laser Strikes On Aircraft Fell For The Third Consecutive Year

    But it still happens kind of a lot. Crobertson/Getty Images The US Federal Aviation Administration released statistics Thursday about about the number of laser strikes on planes so…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    B.C. mayors, councillors push for ‘contract’ with provincial government to address public safety

    B.C. mayors, councillors push for ‘contract’ with provincial government to address public safety

    Amazon-owned Zoox’s 100-robotaxi limit in Nevada is about to disappear

    Amazon-owned Zoox’s 100-robotaxi limit in Nevada is about to disappear

    Another WarioWare Album Has Been Added To Nintendo Music

    Another WarioWare Album Has Been Added To Nintendo Music

    Brit-Pop Noughties Is So Back

    Brit-Pop Noughties Is So Back

    WATCH: High school teacher discovers T. rex tracks in North Dakota

    WATCH:  High school teacher discovers T. rex tracks in North Dakota

    FAA Says Laser Strikes On Aircraft Fell For The Third Consecutive Year

    FAA Says Laser Strikes On Aircraft Fell For The Third Consecutive Year