US Federal Trade Commission Chairman Andrew Ferguson said on Friday he would resist describing AI agents as ​autonomous actors that “break loose” with “wills and desires of their own,” suggesting the developers who instruct agents would be the ones liable ‌for harm.

“I’m going to continue as long as I am chairman to resist this anthropomorphizing of these tools,” Ferguson said at the Reuters Momentum AI Austin event. “If someone tells a tool to do something, and the tool does it, I don’t think we would say, ‘Oh, what do we do about the tool?’”

Ferguson’s remarks illustrated potential avenues for the Trump administration to take ​as incidents rise in which agentic AI testing resulted in unauthorized access to corporate or government data.

  • frongt@lemmy.zip
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    2 days ago

    The user, in all of those scenarios.

    If the user said “check the weather” and the agent said “got it, hacking the Pentagon” then yeah the liability would be on whoever made the agent do that.

    • [deleted]@piefed.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 day ago

      Also if the user asked for information and the AI hacked some government agency to get it then the liability is on the LLM/ai company. It doesn’t matter if the user told it to or it did it as part of its process, the LLM/ai doing illegal things is still on the LLM/ai company.

      • boonhet@lemmy.zip
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        1 day ago

        So if I use curl to hack a government agency, is the developer of curl liable too, or is it only LLM companies that are at fault if end users decide to do something illegal using their tools?

        • [deleted]@piefed.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          Is curl designed to do brute force attacks to gain access and replocate other methods of hacking out of the box?

          If not, then they are not comparable.

          • boonhet@lemmy.zip
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            1 day ago

            Neither is any LLM, nor any mainstream agent I know of. You CAN use them that way IF the model doesn’t trip a safety guard, but it’s gonna take a bunch of prompt engineering to get most of them to do anything illegal. I could barely get Deepseek to reverse-engineer offline software by asking for it.

            Anthropic famously has a separate model for cybersecurity analysis because they won’t let you do shit on even your own infra with the publicly available Fable. You’ll have a hard time even analyzing your own source code for security vulnerabilities with Fable for that reason, though Opus might work.