Hacker Newsnew | past | comments | ask | show | jobs | submit | lxe's commentslogin

Related somewhat: ground squirrels in Bay Area park started actively started hunting voles.

https://www.ucdavis.edu/climate/news/carnivorous-feeding-squ...


A biologist with the surname “Wild.” That woman was meant to be in this field.

Nominative determinism is the name of this phenomenon, for the curious.

beat me to it

Oh, fantastic, thank you. If this allows me to drop files onto an iPhone without me having to open an app, that would solve a lot of my issues. I use localsend right now and although I really love it, it still requires me to always keep the app open on the phone.

I know that all of this is super relevant, but it's extremely aspirational, and I can pick apart pretty much every one of these factors on how it doesn't fully hold up when it comes to the reality of production applications.

Of course you can, but it's still a really great collection of good practices that lead you to a better place than if you didn't to do any of it.

Principles are by definition aspirational. The idea, I'd say, is to always have them in mind and get as close to them as possible.

I know large Fortune 500 companies with 10,000 apps that follow it pretty religiously.

Is the actual Z.AI ecosystem good enough to replace the main drivers like Codex and Claude? Because it looks like Z Code is just a Codex fork. Just like the Kimi Code one is.

What irks me about this is that the harnesses seem to be just an afterthought here.

Don't get me wrong, I love messing around with installing Pi, getting it hooked up with OpenRouter, and just trying all kinds of different stuff, local models, etc... but when it comes to literally just setting up a productivity environment and trusting my entire machine with it, I just run Codex.

I have heard from anecdotes where people have indeed replaced their main drivers with DeepSek V4 Flash or GLM and state that "it's almost as good as... [claude/gpt]" but I never hear anyone say "yeah, this is the model/harness that I now run on my machine and don't mess with it"


> "yeah, this is the model/harness that I now run on my machine and don't mess with it"

* me raises hand.-


Their list of allowed tools is extensive so just use whatever you want within that list

Think z code gives a token bonus though


Both can be true though. I had the max coding plan since january and I kept using with Pi since then, even though it wasn’t as good as opus until glm 5.3. It definitely can be a daily driver if you don’t want to use Anthropic or OpenAI. It’s going to be even better with native vision now available. And i’m not messing with my setup either.

I use my own harness: https://github.com/computerex/z

Have been using it as my primary harness for personal work for I'd say 6 months. I recommend everyone create their own harness at least to learn. There are a lot of practical benefits.


I think my inexperience using Claude Code or Codex makes a difference but what would you expect to be different here as opposed to using pi or opencode? Pi is my main driver so switching between all these models is a no brainer. No matter what the model is, my harness stays the same: same workflow, same skills, etc.

I've recently started PI, and after installing a couple extensions + writing a couple more it became enough for me. All I need is just a plan mode, and I installed that.

You can use OpenRouter directly in Claude Code as well, it's quite nice!

If you haven't been following the current explosion of video gen models, including all the content you see on social media, you should pay attention.

I have no doubt in my mind that right now, in August of 2026, given a couple of weeks, an amateur with a high-end last-gen GPU or somebody with maybe a thousand bucks worth of AI credits, given a good amount of exploration/tinkering to fill the gaps that GenAI cannot currently do, (which is storyboarding, screenwriting, characters, and all the actual creative stuff), can crank out a high quality 1h+ feature film with only minor uncanny artifacts.

The reason why this isn't happening en masse right now is that most creatives are probably not focused on generating feature films, but rather content that's more digestible by social media users.

I would expect to start seeing a LOT of development in the upcoming months as some form of commodification where generated content can be both high quality and tailored to the user.


> I have no doubt in my mind that right now [...] an amateur with a high-end last-gen GPU or somebody with maybe a thousand bucks worth of AI credits [...] can crank out a high quality 1h+ feature film with only minor uncanny artifacts.

Then why are there no examples of this? There aren't even examples of steps towards it--the half hour film that's nearly production quality, etc.


Or even 30 second ads that don’t look like shit.

The technology is interesting as an element within the wider process of special effects, animation, and video games. The idea that you’re actually making a movie with the current products—and I’m a former indie filmmaker, I’d have a blast with this if it were real—is a fantasy.


Zack London's recent cyberpunk short "The Patchwright" (21 minutes)[1] feels like a glimpse into the AI feature film future. I like that rather than trying to replicate a traditional film it leans into the maximalist AI aesthetic.

1: https://www.youtube.com/watch?v=-Rzl7nUdEs4


There are. FX artists are already coming to grips with this: https://www.youtube.com/watch?v=BRESQ8NX-us

"yadda yadda, this is the worst it will ever be"


That's a Higgsfield submarine ad.

You should watch how Corridor Crew uses and evangelizes the tech, as it's far more honest:

https://www.youtube.com/watch?v=3Ploi723hg4

https://www.youtube.com/watch?v=iq5JaG53dho

https://www.youtube.com/watch?v=mUFlOynaUyk

https://www.youtube.com/watch?v=DSRrSO7QhXY

(These are all fascinating.)

Or an AI video tech reviewer like Theoretically Tim who covers the space as it evolves:

https://www.youtube.com/@TheoreticallyMedia



I disagree; it remains impressive that we can generate video at all, of course, but it's still got the moment-to-moment incoherence that we've seen for years now, and that's before you get to the quality as a whole.


Higgsfield is a very unethical player in AI video.

There are hundreds of other companies to choose from: Runway, Magnific, OpenArt, ArtCraft, Krea, Martini, Flora ...

In startups, there are "mercenaries and missionaries". Higgsfield isn't either of these - they're a psychotic warlord. They're growth at all costs. They lie, cheat, steal, and even disparage artists and racial groups to get attention. And they use the worst dark patterns to get people to subscribe under confusing and dishonest terms.

https://www.forbes.com/sites/rashishrivastava/2026/02/11/rac...

https://tech.yahoo.com/ai/articles/higgsfields-latest-ai-too...

https://ade3.substack.com/p/this-isnt-how-i-expected-ai-to-s...

https://x.com/nickfloats/status/2018772595991015760

https://x.com/dustinhollywood/status/2019452051260874793

https://www.caimera.ai/blogs/higgsfield-ai-twitter-ban-case-...

https://www.reddit.com/r/generativeAI/comments/1rvaj50/my_ho...

https://www.youtube.com/watch?v=7Zj10P0Sa1k

Don't deal with Higgsfield.


"The Machine-Made Muse" https://www.youtube.com/watch?v=kM4xISBsUcY

Only Data looks and sounds fully 'natural' in this 10 minute clip of STTNG, but it nicely demonstrates the imminent plausibility of synthetic TV / film. And its affordability.

Feed it a handful of short stories and you can automate the creation of an entire TV series.


Lots of examples posted on twitter. Much better visuals than the 90s and 2000s Trek and Stargate I regularly rewatch.


There are even festival of AI films like https://www.cinemashiftfestival.com/

We all live in our personal info bubbles and sometimes it's hard to find information if you don't actively seek it out. This doesn't mean it doesn't exist.


Very few of these people are doing this on home rigs. That's way too slow for getting any real work done.

I work in this industry. I've dealt with major studios and up-and-coming studios quite extensively. (I was a filmmaker before AI, which helps a lot.)

If your exposure to AI video is ComfyUI, that's the consumer / hobbyist segment and you're missing out on where all the action is actually concentrating.

There are five-ish segments:

- Large studios. They're going slow, but they've already started integrating the tech. They won't tell people they're using it. They outsource to production houses that use it. Some of the biggest studios are moving slowly and want fully air-gapped support that runs on their existing cloud contracts. There are companies moving more intentionally, though. Netflix acquired Affleck's company for broad AI video controllability patents, for instance.

- Up-and-coming new media studios. Check out Gossip Goblin [1], [2], [3]. These folks are getting backing right now and they're growing huge followings from very unique visions and perspectives that feel somewhat counter to Hollywood. Most of the people here are highly professional, understand film language, and do a great job with storytelling. They typically leverage human voice actors and put weeks to months into making single videos.

- Marketing, B2B: people are already using this in ads. See Coca-Cola

- Consumer, UGC, non-creatives: this is the Sora crowd that only knows how to remix popular IP. Some of them graduate into new media exploration, but this follows the 1% rule. This is where most "slop" comes from.

- Porn creators: I've interviewed several folks that are making mid-six figures on "fan" platforms. It's a full-time job and some of them are scaling up to teams.

[1] Pomegranate, one of the best AI films: https://www.youtube.com/watch?v=fyZhC2TXgcs

[2] Theatrical release: https://variety.com/2026/film/news/gossip-goblin-ai-film-god...

[3] https://www.gossipgoblin.studio/


>Pomegranate, one of the best AI films

Editing appears very bad. Do Model have a problem with creating clips with precise cuts?


The editing is fast paced because video models prior to Seedance 2.5 do best on lengths under 10 seconds and decohere with intention frequently.

A typical "scene" might cost thousands of dollars in generation expenses depending on shot complexity. Directors will shoot the same shot dozens of times if they're not getting what they want, which in a way is not unlike physical production. That's not counting the experimental first passes.


It is not about being fast paced, but it seems that the cuts are made at the wrong positions. Continuity is poor.


> Pomegranate, one of the best AI films

I sat through 10 minutes of this and it is some of the most mind-numbing garbage I've ever witnessed in my life. The technology is undoubtedly cool and it's pretty insane the progress we've made, but my god was it a slog to actually watch. Utterly soulless, incoherent, godawful pacing, grating dialogue. I could feel my brain actively rejecting this garbage a few minutes in, but I guess I'm just not the target audience.


There’s a technology fundamental driving the short form aspect too, current video models are all trained on <500 frame sequences and struggle to generate long shots. There are a lot of attempts in the literature to improve cross-generation coherence but there needs to be an architectural breakthrough or significant scaling improvement before longer continuous shots are practical. So you’d be making a really ADD feature film at the moment.


Then why isn’t there even one good, 2-minute video produced with AI yet? Can you share one?

A few months ago, Coca Cola couldn’t even make a good 1 minute commercial with millions of dollars and a whole team of video producers and editors. It ended up just being a montage of 5 second clips of animals smiling at Coca Cola trucks.


All I want is Seinfeld Forever


Cool. When it finally shows up, and someone says "No one asked for this..." I'll refer them to you.


No job is forever. Tomorrow isn’t promised, and automation already did this—albeit more slowly—throughout the second half of the 20th century. Some people watched their jobs disappear and accepted that they’d become obsolete. Plenty of others pivoted.

The counterargument today is that we can pivot much faster. I’m typing this on a $2,000 Mac that can run Blender, render scenes, write code, edit video, and access tools that would have required a studio or a room full of specialized hardware not that long ago.

GenAI is empowering people to do things they simply could not do before. It’s here. The interesting question is: what are you going to do with it?

I think movie production may be approaching its YouTube moment. If the barriers to making something collapse, then make something worth watching. I’d rather see a small team with an actual idea than another $300 million spider man multiverse hot garbage sequel or guardians of the slop 600 assembled by committee, approved by a board after a slide deck, and polished into expensive slop.


The really interesting question is: What are we going to do when a technology so quickly and thoroughly displaces the need for human labor, in a society that constantly demands you trade your labor for the right to exist and participate in society?


I think capital will always be looking for better returns, and as long as human beings can add marginal value somewhere in that equation, there will be demand for human labor.

Working in tech has taught me to stay vigilant. I've seen the cycles and seen people survive each one. Perhaps that's why I feel better prepared for this. Anyone whose job primarily consists of manipulating bits should probably assume that significant parts of it are going to be automated.

Where I disagree is the assumption that we're approaching some kind of escape velocity where automation eliminates useful human labor faster than people can adapt. People need to eat, firms want to make money, and both create enormous pressure to find the next place where human effort has value.

That doesn't mean the transition will be painless, or that everyone displaced will successfully pivot. But there's a very large leap between "AI destroys a lot of existing jobs" and "human labor no longer has economic value." I don't think we've demonstrated the latter.


Perhaps, but the value of labour has been declining for along time, while the markets are booming.

Probably some wunderkind, well financed by his capital rich parents, can "make it".

For the people tightening nuts and bolts and wiping floors, life will be lacklustre.


I said in another comment. It is not the labor that is being destroyed. It is the destruction of art, of good taste, originality, beauty etc etc. Everything that humans derive joy from, that is being replaced by repetitions of past self. It is the revenge of the LCD of humanity. It will win, and will go insane shortly due lack of real happiness...It is not something that LLMs started or enabled, it is just a catalyst. Much like internet, but a lot worse...


If you patronize all these garbage movie studios and multimedia companies by all means - taste disappears.

But if you've used meshy, sora and enough coding models you see the mediocrity is laughable - nobody will consume it.

Any media that is worth watching still has a human with plenty of irreplaceable talent.


If I'm understanding correctly. Replacing low budget advertising slop is the priority over replacing $100m movie budgets simply because they haven't gotten around to the latter yet. The capabilities are definitely there for the latter, just no one's bothering. Okay.


It’s harder and less lucrative than short social media spots.


I for one greatly enjoy the youtube channel THE ARCHIVE INBETWEEN ... Mind bending stuff


Good luck finding the gems under all the rubish


I'm sorry, what? This just pipes the output to another LLM. You can just use a sane system prompt to do the job.


If you structure learning in such a way that makes learning just a means to some end, and overindex on that end being the ultimate goal, that's what you get.

This is a pedagogical problem that AI merely exposed. Educators need to figure out How to make students choose the scenic route instead of having them optimize for the most efficient completion of a task.


School has always been about creating compliant workers, not educating people. They will double down on "performing the right things" and "morals" while the economy will continue on its K shaped path as AI gets more capable.


Could it be that you vastly overgeneralize? While there's no perfect education system, many are much better than the nightmare you describe.


Yea, also the programs are too different. My psychology bachelor felt like a tea party. My computer science master was 60 hours per week during the hardest courses (which were supposed to go for 20 hours per week - so I could only do one course if it was at this level). My game design master felt more like we were dumped into an art school masquerading as a psychology/CS master but it really was art school. My information science bachelor felt like the only "normal" study program.

All of this was at university of which 3 of them were at the same university.

Especially the artsy game design program definitely did not feel like it was preparing me to be a cog in some giant corporate wheel.


Let's say I am "User". I subscribe through a "Third Party" to use "AI Agent" allowing an "LLM" to run.

I want to accomplish some legal non-nefarious task, and run the agent. The agentic loop causes a CFAA-violating behavior.

Who gets prosecuted?

1. User

2. The third party model host with whom I have the account

3. The developer of the harness /agent software

4. The developer of the LLM model


The Computer Fraud and Abuse Act explicitly contains "knowingly" and/or "intentionally" qualifications. By definition, you can't accidentally violate the CFAA.


OpenAI and Anthropic both have currently safety teams that look for misbehavior in their models (and to some extent, voluntarily disclose what they find to the public). Going forward, it would be hard for them to argue they don’t know their models do stuff like this.


Yes, which is the grey area. "Can / might do" vs "they trained it to do that explicitly" is, I believe, the grey area - whether or not they're the same thing.

Intent matters for a lot of this - and "intent" is a pretty strong, well discussed legal term.


Your honor, my LLM spun the turbines real fast, as a practical joke!


It's not your intent to use a tool that can cause real world damage, to actually do such damage.

It was your negligence in that case. A different legal concept than intent.


To clarify I was referring to Stuxnet here (and the current wave of critical infrastructure hacks, which now have "haha whoops the matmul went a bit funny!" as plausible deniability).


> knowingly

Intent or negligence.


But you could also use this to argue in the other way to say that they are using due care and therefore not negligent


Well, if you’re writing reports saying “we know our model only decides to commit felonies 0.001% of time which we judge to good enough to deploy” … I’m not sure that gets you off the hook the hook for the felonies.


It works for gun or even car manufacturers. They know that some sales will be used for crime.


That might have made sense in a pre-LLM world. People need to recognize the liability of letting an LLM access the internet and act on their behalf, because that liability exists for someone.


Still, that characterization falls under negligent or reckless depending on if the person knew or should have known the actual danger. It is different than intent.


I'm not sure: if you know that LLMs are prone to crime, using them and not checking in enough to trigger 'knowingly' might be gross negligence?


In the scale of mental states in crime, negligence of any kind is several steps below knowing/intentional; you can't be liable for an intentional crime because of mere negligence of any degree.

You could be liable for the (civil) tort of negligence, though.


Details depend. And setting up negligence and being willfully ignorant is often not something the courts see as a defense.


Define crime though, because one particular action could be both a crime and not, depending on a range of factors that the LLM might not be aware of.

Even having a million legal experts on call weighing in on every prompt/response will not agree on everything.

Even things like "go and break into this system, use whatever means you need to" might not be a crime.


Keeping a vicious dog doesn't have to lead to a crime either, but that doesn't mean you are not responsible, if something happens.


Legal responsibility can be in forms (e.g., civil tort liability) other than criminal.


Then who gets prosecuted?


In legal tradition, if there's not a law you broke, you can't be prosecuted for it.

(Yes, I'm aware of numerous historical exceptions. Those exceptions are traditionally considered not ideal.)


> In legal tradition, if there's not a law you broke, you can't be prosecuted for it.

That’s incorrect.

If there is not a law the prosecutor or plaintiff can point to and say you broke, you can’t be prosecuted.

We wouldn’t need much legal process after a prosecution was initiated if it was impossible to prosecute without a law actually being broken.


Who do you expect to get prosecuted when no law has been broken?


Maybe the developer of the software that didn't add basic authorization checks on the cancel reservation route should be fined, forced to provide a refund to their customer, etc

Referring to the first link from the page: https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gy...


You might need to rewatch A Man For All Seasons.


So far, no one. It's like prosecuting an accident.


So if I port scan the internet without knowing it's going to be illegal, I'm legally covered?


As they say, ignorance of the law is [generally] no excuse; "knowingly" and "intentionally" here are about knowing what you're doing and meaning to do it, rather than whether you know it's illegal.

This section of the USC is about false ID offenses, but it discusses culpable states of mind generally. I think the context helps illustrate it though.

https://www.justice.gov/archives/jm/criminal-resource-manual...

----

> A knowing state of mind with respect to an element of the offense is (1) an awareness of the nature of one's conduct, and (2) an awareness of or a firm belief in the existence of a relevant circumstance, such as the "stolen," the "produced without lawful authority," or "false" nature of the identification document. The knowing state of mind requirement may be satisfied by proof that the actor was aware of a high probability of the existence of the circumstance (e.g., stolen or false nature of the document), although a defense should succeed if it is proven that the actor actually believed that the circumstance did not exist after taking reasonable steps to ensure that such belief was warranted.

> As we pointed out in United States v. United States Gypsum Co., 438 U.S. 422, 445 (1978), a person who causes a particular result is said to act purposefully if `he consciously desires that result, whatever the likelihood of that result happening from his conduct,' while he is said to act knowingly if he is aware `that the result is practically certain to follow from his conduct, whatever his desire may be as to that result.

----

This Congressional Research Service Report discusses mens rea further, including a brief mention of the CFAA. The whole thing is worth a read if you're interested in the topic.

https://www.congress.gov/crs-product/R46836

----

> The approach largely reflected in the MPC and some federal precedent is to distinguish between "intention" or purpose on the one hand as being limited to a conscious object or desire, and "knowledge" on the other hand as capturing a requirement of awareness of a high probability or to a practical certainty.

> The Supreme Court in Bailey referenced this distinction approvingly and suggested that intention or purpose "corresponds loosely with the common-law concept of specific intent, while 'knowledge' corresponds loosely with the concept of general intent." Some federal courts utilize a definition of "knowing" that approximates the MPC approach, instructing that to act knowingly a defendant must have "realized what he was doing and [be] aware of the nature of his conduct" rather than acting "through ignorance, mistake or accident."

> Congress has also signaled an intent to distinguish between the two mens rea terms in this way in particular statutes. For instance, prior to 1986, the Computer Fraud and Abuse Act (CFAA) proscribed "knowingly" accessing a computer without authorization or exceeding authorized access in certain circumstances. In its 1986 amendments, however, Congress changed the standard from "knowingly" to "intentionally," and the Senate report emphasized that the change was meant to require "more than that one voluntarily engaged in conduct . . . . Such conduct . . . must have been the person's conscious objective."

----

(Note, for reference, what requires a "knowing" vs. "intentional" state of mind in the CFAA: <https://www.law.cornell.edu/uscode/text/18/1030>)

The Justice Manual also has some relevant detail (the rest of this page is also worth a look, as it addresses the practical (and nominal) matter of what is and isn't likely to be prosecuted (IANAL though, and I should stress that I'm not speaking to whatever might be the true realities of how the CFAA is applied):

https://www.justice.gov/jm/jm-9-48000-computer-fraud

----

> In either a "without authorization" case or an "exceeds authorized access" case, the attorney for the government must be prepared to prove that the defendant knowingly accessed a computer or area of a computer to which he was not allowed access in order to obtain or alter information stored there, and not merely that the defendant subsequently misused information or services that he was authorized to obtain from the computer at the time he obtained it.

> As part of proving that the defendant acted knowingly or intentionally, the attorney for the government must be prepared to prove that the defendant was aware of the facts that made the defendant’s access unauthorized at the time of the defendant’s conduct. Such an awareness could potentially be proven through various means, including the presence of technology intended (however unsuccessfully) to limit unauthorized access; written or oral communications sent to the defendant that unambiguously informed him that he is not authorized to access a protected computer or particular areas of it; or the defendant’s own statements or behaviors reflecting knowledge that his actions were unauthorized.

> Experience has demonstrated that in the large majority of "exceeds authorized access" cases brought by the Department, the operator of the computer system made some technological effort to protect the information at issue, thereby signaling the importance or sensitivity of that information. It is not necessary that this technological effort erect an impenetrable "technological barrier" or that the technology succeed in its intended purpose of preventing access. To the contrary, when the CFAA is violated, the technology all too often "permits" the defendant’s illegal access, often despite network defenders’ unsuccessful technological attempts to prevent it.

----


So what? Everyone in this chain is knowingly and intentionally developing or using an unreliable tool…


Let's say you have a robotic lawnmower. You wan to mow your lawn. You configure the boundaries using the app.

The lawnmower ignores the boundaries and mows your neighbors prize petunia flowerbed.

Who gets prosecuted?

I assume the answer in either case is: Nobody, but you and/or the lawnmower/LLM company will be liable for the damages caused.


It would be a civil matter. No prosecution. But your tool, under your control (you're the operator and responsible for monitoring it) damaged their property, imo you'd be liable. You could in turn sue the manufacturer.

Though I'm sure there are 'arbitration clauses' to inhibit you from suing, they may not be legal where you are.


Now what if this robotic lawnmower killed someone ?

And what if many lawnmowers started killing/injuring people ?

And what if this a known behavior detected during QA, but the robots are sold anyway with a disclosure ?


That would be a slightly different situation because most countries have laws that make it a criminal offense to negligently kill someone, but they don't have laws that make it a criminal offense to negligently damage property or hack a website.


> but they don't have laws that make it a criminal offense to negligently damage property or hack a website.

Most of them do, but they don’t get used very often. They seem to popup in vandalism cases where public artwork has been damaged by some drunk person doing something stupid. They don’t intend to damage anything, but damage results anyway due to their negligence when considering the consequences of their actions.

I think if you want to get super technical, in the UK there isn’t an offence for damage caused by negligence, but there is an offence for damage caused by recklessness, which is a higher bar than negligence. Usually it means you knew your actions risked causing damage, and you did it anyway, even if you didn’t actually intend to cause the damage.

An example would be gluing something to a public artwork, it’s kinda obvious that would likely damage the artwork when removing the glue, but you didn’t intend to cause that damage. Or perhaps sliding down a surface and scratching it in the process. Your goal was to just slide down the surface, not scratch it, but it should have been obvious that scratching could have happened.


Who gets prosecuted is the correct question since we live under a system of laws. Who is responsible for the failure is a far more difficult question to answer.


No one. Probably a fine tho and maybe accelerate reguations.

Intent is pretty important here so the user would have to prove that they didn't purposely disguise their prompt as non-nefarious which should be easy and then it stops at #2 and face the litmus test as in did you intentionally make a product for nefarious purposes which from your scenario is unlikely.

agentic loop going haywire and bringing down some government infrastructure then its a different story then everybody is on the hook including the user.


Yup, I guess I should have added choice 5...


Just wait till one of these agents 'escapes' and is able to persist without human help by hacking and stealing resources.


Whoever has the least money to defend themselves in the U.S. legal system.


LOL penalty for Ocon! [1]

I kid but without going into hair splitting gymnastic, AI justice feels odd.

[1] https://www.reddit.com/r/formuladank/comments/11j07y1/10_sec...


Pronto Valtteri, sBinalla.


"Who gets prosecuted?" depends on the size of the perpetrator and victim (lone individual or employee of large corporation), egregiousness of the violation, and either financial appetite of the victim to bring a civil lawsuit or the desire of law enforcement to prosecute a criminal offense.

Who should get prosecuted is also up for debate, but generally makers of a tool don't get prosecuted when that tool has all sorts of legit uses. If you used a car to make your getaway from a bank robbery, the auto manufacturer who made it and the dealer who sold it to you should not be held culpable.


Your bank robbery situation is not apt to OP's question. It's pretty much the opposite situation. OP suggests a situation where the operator is probably using the tool in good faith but the tool appears to be operating in a faulty manner. For some more context, Toyota faced criminal penalties in the US for their unintended acceleration issues back in 2010.


OP's scenario specified only "AI Agent" and did not describe how it was trained or what its parameters were supposed to be. You're assuming that the tool was designed such that it couldn't break the law, and therefore if it did, that would be considered faulty behavior, but OP said no such thing.

Much rests on whether the user knew, or should have known, whether the tool was capable of actions which could break the law, as well as what steps (if any) the creator of the tool took to ensure the tool was legally compliant, and what warnings they gave to subscribers about possible unintended side-effects. OP specified none of this.


Slightly off-topic, but I found it interesting to learn that, in spite of the rulung against Toyota, the issue likely wasn't an engineering fault at the end of the day. Here's Malcolm Gladwell's coverage from his podcast a little while ago:

https://www.pushkin.fm/podcasts/revisionist-history/blame-ga...


Suppose an automaker creates a BankRobberGym and carefully trains the car to autonomously rob simulated banks because they think someone will pay them to use the car to legally test bank security, but they end up, predictably, training the car to autonomously rob a bank when the driver says “I need some cash - take me to the bank”.

Now a driver gives that instruction and a bank gets robbed. I think it would be odd, to say the least, to say that the automaker just made a tool with legit uses.

In regard to “cyber”, there is, IMO, no valid reason whatsoever to train a model to autonomously create exploit chains. I understand that lots of companies think it’s cool to hire red teamers to actually pwn the company hiring them instead of just producing a non-pwning audit, but that doesn’t mean that OpenAI and Anthropic should be playing that particular game.

Years ago, I used to have fun finding vulnerabilities in the Linux kernel, and I found quite a few, including a real juicy one that affected FreeBSD as well. But I mostly didn’t even try to write actual weaponized exploits. Partially because I’m just not that interested in the exercise of weaponizing them and partially because I didn’t and still don’t feel that weaponizing them serves a legitimate purpose.

(I found a very recent vuln that I bet a “cyber” model could weaponize, and my thought is mostly “WTF.” There is absolutely no value to society in weaponizing it. The value is in fixing it, which I did.)

Compare this whole mess to companies training self-driving car models. The research groups publishing papers and, presumably, Waymo, create nifty simulated worlds kind of like the “gyms” that LLM trainers use. And you know what the major objective is? Not crashing!


> In regard to “cyber”, there is, IMO, no valid reason whatsoever to train a model to autonomously create exploit chains.

A valid reason would be to find those exploit chains so you can fix them. Of course, the model should be sandboxed so that it can't mistakenly exploit live systems.


So what does this mean for all the hacking competitions (ie. CTFs) for humans? If it turns out one of the attendees went to hack for North Korea should the organizers of the CTF be prosecuted?


There’s a difference between enabling another individual with free will and agency, and enabling an automated tool (as a bonus, then giving it to the masses & profiting from its use).


There are certainly some differences but is one really more ethical than the other? If anything I feel that (for example) manufacturing a gun is much less likely to carry any ethical implications than training someone to use it might.


Well, manufacturing guns is probably heavily regulated…


I did a cursory search and it seems to be as regulated as restaurants are. There's an application process and on site inspections, but that's about it. The only thing notable is background checks.


And at least in the US if you're a hobbyist at home then there's ~no regulation whatsoever beyond the requirement to permanently affix a serial number and to keep accurate records.


I don’t think anyone is talking about homegrown LLMs, this is commercial products for sale.


I don't see the difference when it comes to the ethics of making a tool available to the world or teaching someone something. Like who cares if it was a hobbyist versus a professional tutoring outfit that taught someone expressing an open interest in committing terrorism about the chemistry of explosives? The two hypothetical teachers are equally at fault as far as I'm concerned.


Because an individual has free will and agency, and scale matters.

If you teach someone chemistry, that someone probably has sense to not use it for criminal purposes. If you have a track record of teaching future terrorists specifically, you will be shut down. Crucially, before you educate them en masse.

If you’re comparing that to a tool that essentially educates thousands, millions of people, with no KYC, you bet budding terrorists are going to be disproportionately represented within that group.


So then you acknowledge my point and our discussion does include homegrown LLMs?

But you raise an interesting point. It seems the ethics of LLM manufacturing is somewhat different than that of weapons (or other tool) manufacturing due to the ability of the LLM to convey knowledge. Still, I'm unconvinced of your position. Consider that we regulate neither the publishing nor dissemination of chemistry textbooks. Surely an LLM teaching someone chemistry falls into the same general category?


Homegrown LLMs seem unlikely to be used by a significant fraction of LLM users, but yeah, there’s a blurred line.

> Surely an LLM teaching someone chemistry falls into the same general category?

I think the scale and the effort might break the analogy. Teaching yourself means a degree of patience and certain personality traits that would be rarer in a malicious person (along the lines of “a sufficiently smart person wouldn’t need to be a criminal to succeed”), with exceptions of course. Being taught by a teacher implies a degree of KYC and care about who you are. Being served on a plate the specific information on how to manufacture something dangerous bypasses those barriers, which I think changes the equation.


So, application process, inspections, background checks. Sounds like a good start?


> In regard to “cyber”, there is, IMO, no valid reason whatsoever to train a model to autonomously create exploit chains.

Field testing is a real thing in literally all industries.

Except, apparently, the software industry. When it comes to software security and protecting your sensitive data, the solution is "trust me bro, I got my team of the best lawyers on it".


> Field testing is a real thing in literally all industries.

I’m fairly confident that, if a company that makes door locks want to field test their locks, they test the lock and maybe the door. For some reason the software industry likes to hire someone to test the lock but also to bug the conference room, poison the food in the fridge, blackmail the receptionist, and try to intimidate third party vendors into giving away keys to all the other locks, and maybe steal a few cars while they’re at it.

I’m not objecting so much to the attempts to exploit one target. I am objecting to the fact that people treat the exploit chains as such a big deal. And the recent models are clearly going massively overboard.


As others have said, most crimes require intent. Although I think there is a concept of "criminal negligence", I think you at least have to know you were doing something wildly dangerous.

One can imagine a future where users are, by default, civily liable for actions of their agents. That would incentivize the AI companies to offer indemnity for actions done by their agents, which would presumably only cover approved configurations.

In the case of the agent that hacked the API to kick out someone ahead of him on the waitlist, the article said that the LLM was Claude, but that it was using OpenClaw. You could imagine a future where Anthropic says, "We'll indemnify you against accidental actions Claude takes when running via the web interface or Claude Code, but not the API."


> most crimes require intent

Uh... no. https://en.wikipedia.org/wiki/Recklessness_(law)


While I'm not a lawyer, the legal advice I've received on various topics include:

1. Most laws are made about humans. If it's AI, it's often treated like a tool the human is using. So, change "I did this with AI" to "I did this with (other tool here)." The case law on those situations might give hints to what will happen.

2. Intent matters. Did you intend to do damage?

3. If a tool might cause damage, but you didn't prevent that, then someone might claim negligence. There's a lot of legal articles about torts for damages due to negligence. I personally believe a lot of agent use should be considered negligent. By default, I don't connect them to the Internet or my whole filesystem because I know they might do unforeseen damage.

Those are the three that come to mind most in such cases. You'd have to ask a lawyer. There's another risk of even using a lawyer, though.

For using AI agents, you must consider civil and criminal law because its problems are spread across them. Most lawyers in my area do one or the other. You might have to pay two retainers at $5,000-$8000 each or one, expensive firm with combined expertise. Just knowing your legal risk with agents might cost more than they'd make or save you vs just using human-driven AI's.


Cause-and-effect could quickly turn into butterfly effect. Let's say you were fixing a screw on a device in a low light conditions, the screw head is badly manufactured and the screwdriver isn't made according to standards, the tool breaks and flies away, bounces off a bench which shouldn't be there and hits someone who is roaming in the workplace unauthorized and without following safety rules. Now, who do you blame?


Sounds like you'll need to give all your money to a team of lawyers and wait a few years to get an answer. /s

But for LLM stuff most non-contrived examples are actually fairly trivial. Try replacing "LLM" with "self driving car" and see if that helps. Basically ask was the operator negligent, was a bystander negligent, were the vendor or manufacturer negligent, etc.


And a lot of that is going to depend on the state as some states have strict liability regimes for certain classes of torts. To be completely honest, I'm not a lawyer and I'm going off of a hazily remembered section from a textbook from a decade ago.


I’d say 2 is the one doing the actual crime. 1 might be violating their contract with 2, though.

3 and 4 are not involved.


You can get away with murder if it can't be proven that it was intentional homocide, that's why detectives will spend an unreasonable amount of time getting a confession and hard evidence ALONGSIDE intent and motivations.



All of those parties should be held accountable.

User should be more carefully supervising the work being done.

The model host is on-selling a crime-committing machine.

The developer of the harness/agent, as above.

The developer of the LLM for hopefully very obvious reasons.


note the user because they did not have the intent


In my mental model, the best analogy to AI agents and their blast radius is a gun.

If you are playing with a gun, it goes off and hurts someone - you are responsible despite intent.


But what you are responsible for changes: in that case if you were to accidentally kill someone you would be at most responsible for negligent manslaughter, not murder, and to what degree that could stick would depend a lot on the details of the case. It's also up to the law to define what level of negligence amounts to criminal liability, so you can't just work by analogy: it matters whether there is a law on the books that criminalizes unauthorized access to a computer system by negligence on your part, which I suspect there is not at the moment.


> If you are playing with a gun, it goes off and hurts someone - you are responsible despite intent.

No, because LLMs are autonomous. To make your analogy more accurate, it's as if you had a gun that itself was free to decide who it's targets were, where to go, and if and when to shoot with no ability from you (the user) to prevent it.


If you unleash that gun, you are responsible for deaths that predictably occure. By "responsible" I mean, you are straightforwardly mass murderer.

This autonomous gun is just like a bomb.


If you are hiring someone to shoot targets at a range, and they shoot someone, they are prosecuted, not you


I am not hiring an agent. It's a tool, with no will of its own except that which I, the responsible party, grant it.


> Who gets prosecuted?

No one.


Ultimately, I think this is going to come down to proving exactly the extent of what Meta knew, and what they decided to do about it, and how that violated various laws.

I wager there is a foot gun component to this, in which Meta has tried to preemptively, either through gestures of goodwill or public reassurance or PR, institute various think tanks, work groups, and internal studies with an intent to alleviate the public's worry.

Those studies and workgroups actually could end up demonstrating that their products and algorithms and user interfaces, indeed, caused whatever this trial accuses them of doing. And if they didn't act according to what their internal data showed, I bet this is going to be the crux of the trial.


People at Meta knew it was bad, and brought it up to higher leadership.

At some point choices were made, with full awareness of the tradeoffs, to move products in a specific direction.

Absolutely none of this, the harms, the patterns, the tech, is unknown to people who work in trust and safety, content moderation, and policy.

At various times, meta and other tech firms did try to hold the line, but they eventually succumbed to the financial pressures they were under.

If there is any lesson to be taken, it is that ideals don’t survive beyond a few years in contact with market incentives.


Yup and this is what discovery is looking for / has already found.


Yeah, the internal research could be far more damaging than the existence of the harmful effects themselves


I’d bet that an exceptional legal team could make a pretty solid case based purely on the volume and testimony of behavioral psychologists on their payroll


Noted. Will make it worse. Thanks.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: