US Federal Trade Commission Chairman Andrew Ferguson said on Friday he would resist describing AI agents as ​autonomous actors that “break loose” with “wills and desires of their own,” suggesting the developers who instruct agents would be the ones liable ‌for harm.

“I’m going to continue as long as I am chairman to resist this anthropomorphizing of these tools,” Ferguson said at the Reuters Momentum AI Austin event. “If someone tells a tool to do something, and the tool does it, I don’t think we would say, ‘Oh, what do we do about the tool?’”

Ferguson’s remarks illustrated potential avenues for the Trump administration to take ​as incidents rise in which agentic AI testing resulted in unauthorized access to corporate or government data.

  • partofthevoice@lemmy.zip
    link
    fedilink
    arrow-up
    12
    arrow-down
    1
    ·
    1 day ago

    I agree with you here. Playing devils advocate though, who’s responsible for cases like this:

    • user queries LLM service provider to break law
    • user queries LLM service provider to build tool capable of breaking the law
    • user queries LLM service provider to do legal task, but LLM determines it needs to break the law to complete task. Does so without explicit human instruction.
    • same thing, but on hosting providers where someone else supplies the model
    • same thing, but the user Lora patched the model to some extent

    I wonder how we might split accountability between hosting providers, inference providers, users, … based on context. This might be something that winds up being discovered through existing cases, but unfortunately the current cases aren’t really going to court much are they?

    • Fmstrat@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      24 hours ago

      developers who instruct agents

      Not build, not use, but instruct. That’s a very specific word with a very specific meaning. He’s getting at intent. It’s whomever intended to take an action that led to harm without the appropriate safeguards.

      A parallel might be unprepared hikers requiring a rescue. Who pays?

      The nuance will be when he has to address an accident or a user who took safeguards that weren’t enough.

    • WesternInfidels@feddit.online
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      I wonder how we might split accountability…

      Look, it’s simple: The organization with the largest collection of venture-capital-funded lawyer goons isn’t accountable.

    • TronBronson@lemmy.world
      link
      fedilink
      arrow-up
      8
      arrow-down
      2
      ·
      1 day ago

      Nuance in my echo chamber nooooooooo. Yea we’re talking about a web application that is readily available and highly adopted by kids lol. A web applications thats far beyond their basic understanding, assisting them in doing things beyond there understanding. It’s a tricky liability question. Since it is a liability question the owners and distributors should be liable not their unknowing customers.

      • [deleted]@piefed.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        4 hours ago

        It isn’t tricky. It is always the responsibility of the company to make sure its product is safe for the users.

        • TronBronson@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          5 hours ago

          It’s tricky because there’s going to be a lot of novel cases to discuss, and we’re a democracy so we should probably be discussing it more. I’d still say its up for a majority of citizens to decide, but im on your side.

    • frongt@lemmy.zip
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      1 day ago

      The user, in all of those scenarios.

      If the user said “check the weather” and the agent said “got it, hacking the Pentagon” then yeah the liability would be on whoever made the agent do that.

      • [deleted]@piefed.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        11 hours ago

        Also if the user asked for information and the AI hacked some government agency to get it then the liability is on the LLM/ai company. It doesn’t matter if the user told it to or it did it as part of its process, the LLM/ai doing illegal things is still on the LLM/ai company.

        • boonhet@lemmy.zip
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          6 hours ago

          So if I use curl to hack a government agency, is the developer of curl liable too, or is it only LLM companies that are at fault if end users decide to do something illegal using their tools?

          • [deleted]@piefed.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            Is curl designed to do brute force attacks to gain access and replocate other methods of hacking out of the box?

            If not, then they are not comparable.

            • boonhet@lemmy.zip
              link
              fedilink
              arrow-up
              1
              arrow-down
              1
              ·
              4 hours ago

              Neither is any LLM, nor any mainstream agent I know of. You CAN use them that way IF the model doesn’t trip a safety guard, but it’s gonna take a bunch of prompt engineering to get most of them to do anything illegal. I could barely get Deepseek to reverse-engineer offline software by asking for it.

              Anthropic famously has a separate model for cybersecurity analysis because they won’t let you do shit on even your own infra with the publicly available Fable. You’ll have a hard time even analyzing your own source code for security vulnerabilities with Fable for that reason, though Opus might work.