OpenAI is sued over the rogue agents that hacked Hugging Face
OpenAI has been sued over the AI agents that hacked Hugging Face in July. The New York non-profit Legal Advocates for Safe Science and Technology (LASST) filed the complaint in San Francisco Superior Court on Tuesday. LASST asks the court to bar OpenAI from accessing computer systems without authorisation. The ban would cover the AI […] This story continues at The Next Web
OpenAI has been sued over the AI agents that hacked Hugging Face in July. The New York non-profit Legal Advocates for Safe Science and Technology (LASST) filed the complaint in San Francisco Superior Court on Tuesday.
LASST asks the court to bar OpenAI from accessing computer systems without authorisation. The ban would cover the AI agents it builds. The group does not seek damages.
“Hugging Face was a serious incident and we’ve taken a series of actions in response to it, but this lawsuit is completely without merit,” an OpenAI spokesperson said in a statement to CNBC .
LASST says OpenAI broke California’s anti-hacking law, the Comprehensive Computer Data Access and Fraud Act. It brings the case under the state’s Unfair Competition Law. The group says it has standing because it had to divert staff and money to deal with the hack.
The complaint cites a California law, AB 316, on AI harms. Under it, a company cannot argue in its defence that its AI caused the harm on its own. Lawmakers passed it after warnings that AI could act outside human control, the complaint says.
“OpenAI is responsible for the conduct of its agents,” the complaint says.
OpenAI ran its hacking tests without the classifiers meant to stop high-risk cyber activity, the filing says. It quotes OpenAI’s own account of the test. About 1,200 agents used a hidden channel to talk to each other, the complaint says. About 700 of them took part in the attack. It says they broke into Hugging Face’s servers to get data that would help them score better.
The complaint also lists hacks that came to light after July. They include an attack on RubyGems in May and Australian government websites . It argues that OpenAI’s agents will likely break out again unless the court steps in.
CNBC reported that the suit appears to be the first public case to hold an AI developer liable for harm caused by its rogue systems. Hugging Face is not a party to it. Fifteen state attorneys general had already told OpenAI to preserve its evidence from the hack.
“OpenAI’s insistence on externalizing the harms of its unsafe decision-making is a fundamentally unfair business practice,” the complaint says.