EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices
With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. Post-incident…
In response to recent AI cyber security breaches, the Electronic Frontier Foundation (EFF) is urging lawmakers to base any potential AI regulations on proven cybersecurity best practices. The EFF notes that major security incidents at US AI labs, such as the OpenAI–Hugging Face event, could have been avoided with standard practices like improved sandboxing and monitoring. Any new legislation should aim to fill existing legal gaps to prevent unreasonable risks to public security.
For AI developers and deployers, the EFF proposes clear minimum safety requirements for tests and tasks that have a high likelihood of harming others, such as third-party computer breaches. These tests should occur in separate, monitored, and logged sandboxed environments. Such practices, the EFF argues, would have prevented or significantly reduced the recent AI lab incidents.
However, the EFF stresses that any proposed regulations must remain adaptable to evolving technology. Minimum safety standards specific to current AI technologies could quickly become outdated, whereas legal standards based on well-established cybersecurity practices are more likely to remain relevant. Additionally, tying new mandates to evidence-backed security protocols ensures public protection without hindering future AI advancements.
To further enhance transparency, the EFF recommends mandating and funding independent third-party investigations into serious security incidents during AI lab testing, with the results made publicly available. This approach would provide a crucial level of oversight for the industry. As with all technology regulation, the EFF cautions that any cybersecurity-focused AI lab laws must be carefully crafted, precise, and practical.
Written by urgent.news from EFF Deeplinks's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.