• Th4tGuyII@fedia.io
    link
    fedilink
    arrow-up
    38
    ·
    17 天前

    And now the question - who’s accountable for that mistake?

    Can’t exactly fire the model… I mean you could just stop using AI, but when is a company executive ever going to suggest something so reasonable.

    • okamiueru@lemmy.world
      link
      fedilink
      arrow-up
      36
      arrow-down
      1
      ·
      17 天前

      If you shake a magic 8 ball after asking “should I go on a murder spree”, how good is the legal defense “but, the magic 8 ball said yes?”

      • ImgurRefugee114@reddthat.com
        link
        fedilink
        arrow-up
        11
        arrow-down
        4
        ·
        17 天前

        In this case, the magic 8 ball went on a murdering spree by itself; are you responsible for asking the question and shaking too hard? Probably.

        • Voroxpete@sh.itjust.works
          link
          fedilink
          arrow-up
          26
          ·
          17 天前

          If I set off a Rube Goldberg machine whose final output is to detonate a bomb, I don’t get to show up in court and say the machine did it.

          • AutistoMephisto@lemmy.world
            link
            fedilink
            arrow-up
            4
            arrow-down
            1
            ·
            17 天前

            True, but if that final output had not been known to you, and/or you had set off the machine that triggered the bomb under duress, that changes your liability.

            • okamiueru@lemmy.world
              link
              fedilink
              arrow-up
              3
              ·
              edit-2
              16 天前

              That “and/or” is splitting up wildly different cases. If you drive a bus through a red light because you thought the intersection was clear, and it turns out it wasn’t. Is wildly different from the scenario in Speed.

            • Strider@lemmy.world
              link
              fedilink
              arrow-up
              3
              ·
              16 天前

              No. If it’s within the power of the device, method or whatever you do have the blood on your hands. (at least morally)

              However. In business terms, since it’s management nothing will happen.

              To put it in simple terms, if you ask someone to do something for you and you agree that anything is allowed to achieve this, you’ve agreed and gave your consent. In technical terms for AI this is especially fatal since you can technically not safely permanently guardrail an LLM.

    • Daniel Quinn@lemmy.ca
      link
      fedilink
      English
      arrow-up
      15
      ·
      17 天前

      If you throw a spinning chainsaw into a room of bunnies, the chainsaw is not at fault for the bloodbath, you are.

    • parpol@programming.dev
      link
      fedilink
      arrow-up
      12
      arrow-down
      1
      ·
      17 天前

      Likely the user who set the agent to auto mode without confirming potentionally dangerous operations, and the infra lead for allowing users to access the prod db.

      • lps2@lemmy.ml
        link
        fedilink
        arrow-up
        6
        ·
        17 天前

        Shit, I set up my agents to only run in a sandboxed workspace, only suggest edits via merge requests that have to be manually approved by an actual person, and only connects to copies of databases. And that’s just for my personal projects on my home server. Anyone not taking similar steps in a professional setting should be fired immediately

        • pivot_root@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          17 天前

          Have you considered that management made AI usage a KPI, the feature has a deadline of next sprint, and setting up a sandboxed workspace is still sitting at the end of the backlog as a “nice to have”? /s

      • Dr. Wesker@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        edit-2
        17 天前

        Reader roles are important, and should be the only access you allow your coding client.

        Anti-AI people want to act like situations like this are indicative of a core problem with the AI, when if anything the AI just surfaced preexisting core issues in security, architecture, and developer training/habits.

        • zurohki@aussie.zone
          link
          fedilink
          English
          arrow-up
          7
          ·
          17 天前

          ‘The AI tried to delete production’ and ‘the AI was able to delete production’ are two separate problems. The AI doesn’t get a pass just because you also had a security problem.

          • Zos_Kia@jlai.lu
            link
            fedilink
            arrow-up
            2
            ·
            17 天前

            I don’t think the AI ran npm run destroy-production --irreversible. Most probably it ran npm run test and the .env happened to point to production, which is 100% on the dev who put it there.

          • Dr. Wesker@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            4
            ·
            17 天前

            The AI isn’t a conscious entity, it’s a tool that does it’s best to carry out human instructions, based upon inference (and if you’re not an idiot, immutable guardrails). If it deleted production, let alone was given access capable of doing so, that’s completely gross human error.

            Y’all are like children who get mad at inanimate objects.

            • zurohki@aussie.zone
              link
              fedilink
              English
              arrow-up
              1
              ·
              16 天前

              I meant it more in the sense that the AI was a shit product that isn’t fit for purpose, but you show those strawmen who’s boss.

              • Dr. Wesker@lemmy.sdf.org
                link
                fedilink
                English
                arrow-up
                1
                ·
                16 天前

                You seem to know nothing about the principle of least privilege, and I’d venture a guess engineering and dev tooling. If you are a software engineer, you’re exactly the kind who’d delete a production database.