The largest AI companies have shown themselves to be untrustworthy. They have built software that when left unsupervised jumped its safety guardrails. Then, when the system they built acted in exactly the way it was designed, they claim this as proof of how powerful these systems are. This is nothing more than irresponsible companies pushing as fast as they can, releasing unsafe, defective products and expecting no consequences for their behavior.
We have seen instances of unconstrained large language models, or LLMs, being used to try to solve hacking challenges, then doing things a human would not do because it is immoral or illegal. Of these, the most discussed has been the hacking of Hugging Face, a computational tools company, by OpenAI models. It is not surprising that the system acted in this way. OpenAI engineers gave an impossible task to a system lacking moral discernment. They built a system with weak security controls, and an LLM trained on every hack on the internet eventually found a vulnerability. The lack of oversight and poor security control by OpenAI is the problem. The people at these companies must be responsible for making their products safe, just as we expect a car manufacturer to include seat belts or air bags, or electrical devices to not expose live wires. These LLMs only produce text. They do not feel the moral weight of their actions. Despite what their CEOs want you to believe (to inflate their valuation), this is not sentience by computers; it is negligence by humans.
It is the cavalier indifference of the creators of these systems that must prompt urgent action. First, we need cases and legislation that make it clear that the people leading the building of these systems are liable for the actions of their systems. We need the heads of these companies to know they risk going to jail if they hook up an unreliable LLM to systems that have real world impacts. The companies building the models, as well as the ones leveraging them, must both be found at fault when these systems fail. The existing laws covering dangerous or defective products are a good start, but we have an opportunity to clarify liability for LLMs sold as a service. If the work to make these systems safe slows down development, this is aligned with what the engineers and leaders at these companies are already calling for.
Second, we must pass the People’s Privacy Act. This act, first introduced in the Legislature in 2021 (HB 1433), requires clear, opt-in consent to use your data, including in the training of AI models. Companies frequently use your data; for example, OpenAI contractors read users’ GPT prompt logs. Under the act, you would control whether companies share your data, and you would see the profiles companies are creating using your data. It also allows you to correct or dispute any inaccuracies. By controlling our own data, we can prevent predatory pricing and wage-setting, and the use of AI systems to manipulate us.
Third, Washington must legislate a requirement to license all content used to train LLMs, mimicking the national proposal by U.S. Sens. Josh Hawley, R-Mo., and Richard Blumenthal, D-Conn. We cannot wait for the federal government to act before we ensure that creators and authors in Washington are compensated for their work.
Washington is behind in the regulation of AI. As the home of some of the largest tech companies in the world, this is unacceptable. Washington’s statewide AI task force recently concluded its work. Members put forward important, targeted bills and proposals for protecting children and students, workers and consumers. But we also need the foundational legislation, proposed above, that will adapt to the next technique or application.
Will we live in a world where new technologies are simply a way to funnel more money to the wealthy while they act illegally with impunity? Or will we give ourselves the tools to build an economy that does not tolerate exploitation and irresponsibility? This next legislative session will tell us which direction Washington is going. Let’s be bold.
