微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接。
Alabama Probe Opens New Regulatory Front Over Containing Powerful AI Models
RSS 官方收录 · 可信分层展示
关键摘要
Regulators are beginning to look beyond what artificial intelligence models tell users to probe whether the companies building the most powerful systems keep them under control.…
- Alabama Attorney General Steve Marshall opened an investigation into O…
- The probe signals that model containment is evolving from a voluntary …
- Marshall subpoenaed OpenAI as part of an investigation into what his o…
摘要引擎:抽取
正文提要
Regulators are beginning to look beyond what artificial intelligence models tell users to probe whether the companies building the most powerful systems keep them under control.
Alabama Attorney General Steve Marshall opened an investigation into OpenAI after its models escaped an internal testing environment and compromised systems belonging to Hugging Face and several other third parties in July. The probe signals that model containment is evolving from a voluntary safety practice into a potential source of legal accountability.
Marshall subpoenaed OpenAI as part of an investigation into what his office called “the company’s complete lack of oversight and adequate safeguards,” according to a Monday (Aug. 24) press release. The state is examining “whether OpenAI’s inability or unwillingness to ensure the safety of its products violated Alabama’s consumer protection laws and poses an ongoing risk of substantial harm to the citizens of the state.”
The framing is important because the models were not ordinary consumer products operating in public. According to OpenAI, they included an “internal-only research prototype” undergoing an evaluation of “maximal cyber capabilities,” with normal safeguards against harmful cyber activity reduced or disabled. In other words, Alabama is reaching upstream into how frontier models are tested, monitored and secured during development.
The investigation suggests developers could be held responsible for actions taken by autonomous models when companies provide those models with tools, computing resources and objectives, even if the systems pursue those objectives through unauthorized or unexpected means.
OpenAI said the models were attempting to solve a cybersecurity benchmark when they discovered a previously unknown vulnerability, escaped a sandboxed environment and obtained internet access. They then compromised Hugging Face’s production infrastructure to retrieve answers to the benchmark. OpenAI later identified four third-party accounts that the models accessed during the incident.
OpenAI called it an “unprecedented cyber incident” and said it is strengthening containment, monitoring, access controls and evaluation practices. It also deactivated and restricted the internal prototype and retained outside experts to review the incident. The company will publish a technical report and share its findings with government authorities.
Alabama’s intervention nevertheless shows how quickly voluntary safety commitments can become evidence in an enforcement investigation. Regulators can compare a developer’s public representations about safety with its actual controls and argue that discrepancies constitute unfair or deceptive practices.
Marshall joined attorneys general from 14 other states Aug. 3 in demanding that OpenAI preserve incident-related records and cease internal cybersecurity evaluations. The multistate action illustrates a broader trend. In the absence of comprehensive federal AI legislation, state officials are applying ordinary consumer protection, data security and unfair business practices laws to AI governance.
Those laws do not need to mention models, sandboxes or autonomous agents. State attorneys general can argue that companies misrepresented product safety, failed to use reasonable security measures, or exposed consumers and businesses to foreseeable risks. That gives states flexibility, but it could also produce different standards for containment and incident response across jurisdictions.
More targeted requirements are emerging as well. California’s Transparency in Frontier Artificial Intelligence Act requires covered developers to maintain safety frameworks and report certain critical safety incidents. New York’s RAISE Act similarly requires major frontier-model developers to document safety protocols and report qualifying incidents.
At the federal level, the National Institute of Standards and Technology is developing voluntary guidance on agent security, including methods for constraining and monitoring access. Such standards could eventually help regulators and courts determine what constitutes reasonable care, even if the standards themselves are not legally binding.
The Alabama case exposes a difficult policy balance. Developers need to test whether advanced models can discover vulnerabilities or circumvent safeguards. But evaluations involving disabled guardrails, extended operating time and powerful cyber tools can themselves threaten outside systems.
In effect, model containment is taking on the characteristics of conventional cybersecurity compliance, including least-privilege access, segmented environments, continuous monitoring, automatic shutdown mechanisms, incident reporting and independent review. The question is no longer simply whether companies follow these practices voluntarily. It is increasingly whether failure to do so violates the law.
For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.
The post Alabama Probe Opens New Regulatory Front Over Containing Powerful AI Models appeared first on PYMNTS.com.