EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices



With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. 

Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public’s security.

When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else’s computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test environment, disconnected from other systems, and be monitored and logged. Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.

That said, any proposal must be flexible enough to evolve with changing technology. Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time. Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.

Strong legislation should also mandate and fund independent third-party investigations into any serious security incidents that may occur during AI labs’ tests of new tools, and make reports of these investigations available to the public. This important transparency measure would go a long way toward providing public oversight of the industry.

As with any technology regulation, those targeting cybersecurity practices at AI labs must be careful, precise, and practical.



Source link

  • Related Posts

    Waymo says Singapore will be its next international robotaxi city

    Waymo says it will launch a robotaxi service in Singapore in 2028, as the Alphabet-owned company continues to eye overseas markets for expansion. Waymo’s vehicles will begin arriving in Singapore…

    Continue reading
    The AI Slowdown Debate Crashed Salesforce’s Party

    Decked out in purple and plaid, Gwen Stefani belted her 2002 single “Underneath It All” to a packed conference center in San Francisco on Tuesday morning—but she was just the…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Waymo says Singapore will be its next international robotaxi city

    Waymo says Singapore will be its next international robotaxi city

    H&M Holds the Line in London as PETA Protesters Crash Runway Show

    H&M Holds the Line in London as PETA Protesters Crash Runway Show

    Carney embraces EU associate membership proposal as Trump pushes Canada closer to Europe

    Carney embraces EU associate membership proposal as Trump pushes Canada closer to Europe

    The AI Slowdown Debate Crashed Salesforce’s Party

    The AI Slowdown Debate Crashed Salesforce’s Party

    The GE9X’s Mid-Seal Issues Aren’t Expected To Delay The Boeing 777X’s Service Entry, CFO Says

    The GE9X’s Mid-Seal Issues Aren’t Expected To Delay The Boeing 777X’s Service Entry, CFO Says

    Twitch CEO expects GTA 6 online multiplayer will launch next year, which if accurate would leave only the PC port’s arrival point up in the air

    Twitch CEO expects GTA 6 online multiplayer will launch next year, which if accurate would leave only the PC port’s arrival point up in the air