720-891-1663

Is AI Out of Control?

I don’t know but let me give you some data and you decide.

Nvidia announced an AI agent safety platform which they and partners like Jensen (“what, me worry?”) Huang hope some people will adopt. Why? Read the next paragraph.

Florida’s Attorney General James Uthmeier has asked for an emergency injunction against OpenAI and ChatGPT, claiming the company doesn’t have the ability to properly regulate its own technology.

It is unclear whether states can legally restrict AI companies and it will certainly offend Florida’s most famous resident. The request is based on an Axios article that says that OpenAI and Anthropic are facing tens of thousands of security incidents with their models, most of which remain hidden from the nosy eyes of the public.

Credit: Gary Marcus

Apparently, OpenAI, Anthropic and security researchers are finally beginning to be concerned that maybe, they might be liable and possibly should at least investigate what is going on. From the Axios article:

Are these events illegal? That is unclear because Congress is unable to understand technology and only likes to do things that don’t require a lot of nuance. The problem is that existing laws apply to people and companies and not pieces of software. In fact, the software industry has thrown billions of dollars, over the years, at Capitol Hill to make sure that the laws say that software makers are not responsible for what their software does or doesn’t do. The president, of course, doesn’t want to regulate AI at all. Some states have a different point of view, like bright red Utah.

Does any of this have anything to do with Jared Kushner’s brother Joshua’s multi-billion dollar investment in OpenAI? Or Jared’s AI startup Brain Co, which has a strategic partnership with OpenAI? Or any number of other financial connections to the administration. I don’t know.

Credit: Gary Marcus

OpenAI said that after the Hugging Face “incident” they decided that they needed to do damage control, so they are doing a study, which, of course, will take many months to complete. Most cases investigated so far, they say, have been “lower severity”. Whatever that means. It also means, although it doesn’t admit this, that some of the cases must have been “higher severity”.

I wonder how long the lawyers pondered over those words?

Credit: Gary Marcus

As people expand the use of AI, they are deploying MCP (Model Context Protocol) servers to connect AI to their company’s crown jewels – their production environment. Do they have a written and adopted governance plan – before they did this? Likely neither before nor after.

After all, WHAT COULD POSSIBLY GO WRONG WHEN YOU CONNECT A ROGUE AI TO THE IT ENVIRONMENT THAT KEEPS YOUR COMPANY RUNNING?

For example in a report quoted in Infosecurity Magazine, more than 15% of the 5,095 MCP server domains they looked at resolved to IP addresses outside the US. The MCP protocol has no concept of geolocation. So, do you even know what continent your AI is talking to?

Credit: Infosecurity Magazine

So, going back to my original question, is AI out of control? What do you think? I know what I think. If you think that maybe you need to wrap your arms around your use of AI, give us a holler.

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *