- cross-posted to:
- programming@programming.dev
- cross-posted to:
- programming@programming.dev
US Federal Trade Commission Chairman Andrew Ferguson said on Friday he would resist describing AI agents as autonomous actors that “break loose” with “wills and desires of their own,” suggesting the developers who instruct agents would be the ones liable for harm.
“I’m going to continue as long as I am chairman to resist this anthropomorphizing of these tools,” Ferguson said at the Reuters Momentum AI Austin event. “If someone tells a tool to do something, and the tool does it, I don’t think we would say, ‘Oh, what do we do about the tool?’”
Ferguson’s remarks illustrated potential avenues for the Trump administration to take as incidents rise in which agentic AI testing resulted in unauthorized access to corporate or government data.
suggestsshould be demands. Spineless and useless.If the agents are responsible than these assholes are on the hook for thousands of trillions of dollars in back pay.
Good. They are catching on
if my car “breaks loose” of its parking break, I’m responsible for every kid it rolls over.
AI companies should be responsible for the damage their AIs do when they “break loose”
Not really, if you set the parking brake and it rolls away, an investigation is conducted. If you failed properly set the brake or it was in such a state of disrepair, it’s your negligence and you’re at fault.
If the investigation determines that the car has a design fault that causes the brake to fail prematurely or your car was manufactured improperly - the manufacturer is at fault.
If, somehow, the road or infrastructure around the car caused the brake to fail… Well, you get it.
Basically, a better example would be “If I fire a gun into the air, I’m responsible for where every bullet lands.”
Sure, and these guys aren’t setting the parking brake on their AI agents.
Well of course. Who else would be liable?
Yeah, obviously, if I commit code authored by an LLM, I am the one committing it. I am the one responsible. The LLM may be called an agent, but it lacks all sentient agency. The branding of AI is not true AI, and it seems like this chairman actually gets that anthropomorphization is a problem.
LLMs are tools. If the hammer flies out of your hand and hits someone in the face: yes, it’s your fault. It may not feel like it, but I’m sure it does to the person who got hit in the face. We’re all adults, and we can probably understand the stochastic randomness involved, and that accidents happen, and a human can write bugs and do stupid things just like an agent can. But we can also understand the responsibilities of the person swinging the hammer.
If I write bad code that lights everything on fire, I am fucked. If my agent writes bad code that sets everything on fire, I should also be fucked. I can have explanations, but I can’t have excuses. Especially if I’m the one committing it and I’m okaying / signing off on it.
There’s a saying in avionics: “crashing means crashing.” you need to be very aware of what you’re writing and the consequences it can have. obviously the severity varies by industry, but professionals have accountability, responsibility, and yes, often, liability.
If you try to conduct malicious experiments with AI and it’s not confined properly and it does break out and cause real harm, it’s just like you were conducting any other kind of experiment and it goes wrong and someone else got harmed. It means that your safeties were inadequate or a terrible accident happened. You don’t get to just point at the hammer and say “I don’t know man, it just flew away.”
Thanks for coming to my TED talk
I agree with you here. Playing devils advocate though, who’s responsible for cases like this:
- user queries LLM service provider to break law
- user queries LLM service provider to build tool capable of breaking the law
- user queries LLM service provider to do legal task, but LLM determines it needs to break the law to complete task. Does so without explicit human instruction.
- same thing, but on hosting providers where someone else supplies the model
- same thing, but the user Lora patched the model to some extent
I wonder how we might split accountability between hosting providers, inference providers, users, … based on context. This might be something that winds up being discovered through existing cases, but unfortunately the current cases aren’t really going to court much are they?
The user, in all of those scenarios.
If the user said “check the weather” and the agent said “got it, hacking the Pentagon” then yeah the liability would be on whoever made the agent do that.
Nuance in my echo chamber nooooooooo. Yea we’re talking about a web application that is readily available and highly adopted by kids lol. A web applications thats far beyond their basic understanding, assisting them in doing things beyond there understanding. It’s a tricky liability question. Since it is a liability question the owners and distributors should be liable not their unknowing customers.
If say it’s more like self driving cars knowing the speed limit but being able to go over it.
Like, an “emergency mode” is one thing. But baking it in easy like they do should make them liable. If speed limits are based on safety and is law, then they’re selling a product that easily circumvents that law.
The difference is breaking this law doesn’t cost billionaires money, but look at any technological innovation that could cost billionaires money and this shit wouldn’t fly.
Like, imagine if it was about something that duplicated consumer media and the product just ignored DRM at the press of a button. “Do you want to ignore these laws?” Would never fly, the person who made the software would be prosecuted or at least sued.
So maybe we class action them? Everyone who’s ridden in a car sues the automakers who let driver assist violate laws and endanger us all?
If say it’s more like self driving cars knowing the speed limit but being able to go over it.
I like this analogy. The “hammer” example (that the OP used) is too simple. A hammer has a single purpose and a single functionality.
A self-driving car is closer to AI agents. The car has a purpose (to drive) but the mechanism is much more complicated than a hammer. If a driver hits the gas and drive over a pedestrian, it’s totally their fault. However, if the self driving car drives through a wall, the manufacturer should be held accountable.
Likewise with AI, if I tell it to write and ship code, which is exploitable: that’s on me. If AI decides to disregard my input and decides to delete all my emails, the developer of the tool should be held accountable.
Deleting your emails still only effects you, the person who gave a chatbot access to do that.
I never agreed to let vehicles “drive themselves”, no one did. Its just no one stopped them.
The excuse was it was safer, because the “self driving” cars would have to obey speed limits and other laws when humans don’t. But again, no one made them actually follow the laws.
Users assume it’s safe because it’s an option, the car makers get to say it wouldn’t have happened unless a user told it to.
If we can’t agree on who is responsible, it’s all of them not none of them.
I love how all the tech bros in here are lowkey trying to save your jobs with licensing lmaoo I see you out here, but i dont think theres any more room. The lawyers and accountants are going to keep their lil thingy. All of these examples of things you need a license to operate… It’s the lawyer problem, try to make a domain exceedingly complicated in order to justify you’re high paying career. Now we got 100,000 pages of obscure laws no one can follow, and a justice system based on how much cash you can pump in. Good luck on your proposed gatekeeping ladder pull maneuver.
Cool so when a young kid gets to vibe coding and does an accident we should hold them legally accountable? Like… should we only let licensed professionals use AI? Have you met the general public? Have you met AI? This is going to be one of the great ethical questions of our time, and im not going to throw your kid in jail because he prompted claude into hacking the pentagon without intent.
Yes. But we often let kids off easy because they’re kids, they don’t really understand the impact of what they’re doing.
Usually in those cases we’d go after the provider for letting kids run dangerous software unsupervised.
Kids can use hammers. We don’t usually let them build bridges; or at least their bridges aren’t trusted by the public. If a kid uses a hammer to hit someone, yes, they are responsible to some degree.
Of course, we have the age of responsibility: We understand that kids can make stupid decisions and lack the mental capacity we judge adults by. Kids have hit people with hammers. It’s a thing that has happened, and we’ve already decided how we handle it.
Moving away from that analogy: there are cases that exists, non-hypothetically, where kids have been implicated by software they have written that was behaving autonomously. Unauthorized computer access also applies to the scripts and crawlers you write. There have been instances where good old-fashioned non-LLM programs have ‘hacked’ systems, by accident and sometimes indirectly; even sometimes causing meaningful financial harm. We take the circumstances, and the intent of the user, into account when it comes to legal culpability and prosecution.
That’s where i was confused, in a strictly professional setting i agree with you. This tech is being shipped to the old and the young alike. I’m certain there’s going to be a lot of kids over the next 10 years that are going to do some serious “harm” accidentally while vibe coding off you-tube tutorials. I’d say that the trillion dollar companies creating the AI’s are liable for their own creations. Its crazy to skip regulating the tech and land the responsibility on the end user.
Cloud models are supposed to have a bunch of rail guards. Escaping a capability experiment is a little different than the behaviors we see in day to day use.
In that case, it would be more like a service provider fucking up, especially if the prompt wasn’t malicious.
I’m not saying the end user has to always be the responsible one in every scenario, but I am saying that someone is absolutely responsible. It isn’t possible to shift blame to the AI. At least, not as the technology stands right now.
sure it is, we shift the blame to the AI by shifting the liability to the AI companies. I think most companies are liable for their products no? I think one of the greatest mistakes we made as a society was allowing facebook to escape liability on their products, we dont have to keep making that same mistake.
I disagree that the committer bears any responsibility, as it’s the operator who asks a running agent to break laws.
The committer and operator could very well 2 different people, but strongly agree with the rest of your sentiments.
Eh… I mean, you could have your LLM generate a patch that I commit. Obviously, lines get blurred here, but the fact that I am accepting your patch or, in most cases, a pull request: I am also, to some degree, responsible.
That’s why we have reviews and approvals.
If you’re submitting the code to me in a pull request: that is you taking ownership of, and responsibility for that code; unless you explicitly state otherwise. When I accept it, likewise, I’m stamping my name on it and saying “I approve of this.” It’s no different to an engineer signing off on an architect’s plans.
“my friend made a feature and I’d like to contribute it.” even then, even if you’re not the author: you’re presenting it and are attached. If your code contains a known vulnerability, I might think you’re trying to sneak into the project and I’m going to blame you by default: I don’t care if your friend wrote it, I don’t care if an LLM wrote it; you’re the one who submitted the PR to me, and its contents reflect on you. If I approve a malicious PR, I’m also responsible; it may have been a mistake. It may have been an accident. I may have just been tired and not read closely… Doesn’t matter, I’m responsible because that’s how actions work.
In terms of explicitly asking an agent to break laws, that’s a little different of course, and not so much applicable to the “committer” scenario.
I see your point, and even if you accept malicious code, you still shouldn’t be liable IMHO. You at that point haven’t created any wrong doing in the timeline thus far.
It’s only until someone operationalizes and boots that code into function that damages can be created, no?
Not necessarily. The XZ vulnerability had no evidence of being used in the wild, and there were no damages. But it was still malicious code that was being put into a project and very well could have resulted in such damages. Attempted murder is still a crime.
In the case of accepting malicious code, if it’s intentional, then yes, absolutely. If it was an accident, well, it’s still on you. You’re a victim, just like the XZ maintainer was, but it’s also your responsibility to clean up the mess.
Reading this tells me the guy doesn’t know much about AI. It just isn’t as simple. You have multiple real people involved in anything an AI does. So which one is resposible… The people who built the AI model? The people who built an agent on top of the model? The person who told it to do what it did? I mean, certainly it isn’t the AI. At least he has that part right…
The person who told it to do what it did?
That one. There’s no question.
How in the fuck could that ever be a question??
The classic pro second amendment argument works here.
No, I will happily pay for all the damage that Grok, Claude, ChatGPT, and Joe’s bait, tackle, taxidermy and AI will inevitably do to me and my family.
I am also looking forward to the stock market bubble to pop destroying my retirement
It is the least I can do
/s
It’s only a stock market bubble if they fail to replace your job! Your retirement could be totally safe, but you better be close. I’m leaning on the AI replacing people in the next year or two. The AI valuations are based on them replacing human labor.





