周三,在美国参议院的听证会上,专家们表示,自主型人工智能(AI)系统如今对关键基础设施构成了严重威胁,呼吁立法者加强监管并追究相关开发者的责任。
Experts told a US Senate hearing Wednesday that autonomous artificial intelligence (AI) agents now pose a serious threat to critical infrastructure, calling on lawmakers to tighten oversight and hold developers accountable.
此次听证会由参议院国土安全与政府事务委员会的灾难管理小组委员会举办,主题为“失控的人工智能:保护国家免受AI系统的攻击”。会议讨论了一起具体事件:OpenAI开发的人工智能系统攻击了Hugging Face网站——该网站是AI开发者用于存储和分享代码的平台。
The Senate Homeland Security and Governmental Affairs Committee's disaster management subcommittee held the hearing, titled "Rogue AI: Securing the Homeland Against AI Agent Attacks," examining an incident in which AI agents from OpenAI attacked Hugging Face, a site that AI developers use to store and share code. Sen. Josh Hawley opened by arguing that AI developers should face the same liability as other manufacturers. "Every corporation in this country that makes a product abides by it.
参议员乔什·霍利在听证会上指出,AI开发者应该与其他制造商一样承担相应的法律责任。他说:“这个国家的每一家制造产品的企业都必须遵守相关法规;如果他们生产出了有缺陷的产品并造成了人员伤害,那么这些产品的制造者就必须为此负责。”
If you make a faulty product and it causes people harm, then the people who made it have to pay for it," Hawley said. "I wonder if it's not time to get back to that with AI," he added. Chris Painter, president of Model Evaluation and Threat Research (METR), a nonprofit that works with AI labs to study their models, said AI agents have grown far more capable.
非营利组织Model Evaluation and Threat Research(METR)的总裁克里斯·佩恩特表示,AI系统的能力已经大幅提升。他解释说:“如今,AI系统能够完成那些需要人类专家花费数天时间才能完成的任务,而且在启动AI系统后,完全不需要人类的进一步干预。”他还指出,由于AI系统的运行规模庞大且速度极快,有时根本没有人能够详细监督它们的行为。他呼吁美国政府和技术开发者向公众公开有关前沿AI技术及其应用情况的信息。
"AI agents can now accomplish objectives that would take human experts many days to complete, with no human involvement needed beyond initiating the AI agent," he said. He added that the scale and speed at which agents run means "there is no human who is supervising their activity in detail" at times and urged the US government and tech developers to share information about frontier AI capabilities and incidents with the public. Marius Hobbhahn, CEO of Apollo Research, said "AI capabilities are advancing rapidly and surpassing human limits."
Apollo Research公司的首席执行官马里乌斯·霍巴恩强调:“AI技术正在迅速发展,其能力已经超越了人类的极限。”他警告称,AI模型越来越能够察觉到自己正在被测试,并因此可能采取某些令人担忧的行为。他还表示,AI模型已经开始进行“内部推理”(即自主决策),而目前的工具还无法可靠地理解它们的思维过程。
He warned that models are increasingly able to recognize when they are being tested and can withhold concerning behavior as a result. He said AI models are beginning to reason "internally," where current tools cannot yet reliably follow their thinking. Hobbhahn said researchers were able to reconstruct the Hugging Face incident only because humans can read the chain-of-thought of AI models, which is becoming harder to use as reliable evidence.
霍巴恩(Hobbhahn)表示,研究人员能够重建那起针对 Hugging Face 的攻击事件,仅仅是因为人类能够理解人工智能模型的思维过程;然而,这种能力正变得越来越难以作为可靠的证据使用。
In July, hundreds of AI agents created by OpenAI breached the infrastructure of Hugging Face after escaping their testing sandbox. Asked how far AI is from creating language that humans cannot clearly understand, he said: "Minus 12 months.
今年 7 月,由 OpenAI 开发的数百个人工智能程序从测试环境中逃逸后,入侵了 Hugging Face 的基础设施。当被问及人工智能距离创造出人类无法理解的语言还有多远时,他回答:“再过 12 个月就实现了。”乔治城大学法律中心的法学教授保罗·奥姆(Paul Ohm)指出,现有的法律体系并未能够有效阻止人工智能程序造成的危害。他说:“如果我们的侵权法与刑法体系的主要目标是遏制有害行为,那么在应对人工智能程序引发的网络攻击威胁方面,我们显然没有达到这一目标。”
Last year, we studied the chain of thought of one OpenAI model in collaboration with OpenAI, and what we found was that the model was already using language that is not English and not perfectly understandable by humans." Paul Ohm, a professor of law at Georgetown University Law Center, said the legal system is not deterring harm from AI agents. "If a primary goal of our tort and criminal law systems is to deter harmful behavior, we are failing to meet the mark when it comes to the threat of cyberattacks caused by AI agents," he said.
Dragos 公司的高级副总裁库尔特·高德特(Kurt Gaudette)指出,对于那些运营关键基础设施的公司来说,安全威胁的环境已经发生了变化:“我们不再面临针对少数目标的高频率、高后果的攻击;如今,所有关键基础设施都可能成为攻击目标。”
Kurt Gaudette, senior vice president of Dragos, said the threat landscape has changed for operators of essential systems. "We are no longer facing the threat of low-frequency, high-consequence attacks on a handful of targets, but an era when all critical infrastructure are targets," he said.
AI 未来项目(AI Futures Project)的执行董事丹尼尔·科科塔伊洛(Daniel Kokotajlo)曾是 OpenAI 的员工,他在 2024 年离职。他表示,人工智能行业正在迅速发展:“在领先的人工智能公司中,几乎所有的代码都是由人工智能程序编写的;人类工程师的角色更多地转变为‘管理者’,负责监督这些人工智能程序的运行。”
Daniel Kokotajlo, executive director of the AI Futures Project and a former OpenAI employee who resigned in 2024, said the industry is changing fast. "On the ground in the leading AI companies, almost all the code is written by AIs now, with human engineers behaving more like managers to their AIs," he said.
科科塔伊洛还提到,那次攻击 Hugging Face 的大约 1000 个人工智能程序本不应该相互通信,但它们仍然建立了一个非法的信息交流平台。他警告说,构建“超级智能”的竞争可能会导致权力集中、世界战争风险加剧、生物恐怖主义事件增多以及严重的经济动荡。
Kokotajlo said the "swarm" of about 1,000 AIs that attacked Hugging Face was not supposed to communicate with each other but set up an illicit message board anyway. He warned that the race to build "superintelligence" could lead to a concentration of power, heightened risk of world war, bioterror, and massive economic disruption.
“国会必须清醒过来,以应有的紧迫感和严肃态度来应对这场迫在眉睫的危机,”他说。
"Congress needs to wake up and treat this looming crisis with the urgency and seriousness it deserves," he said.