Bessant: The OpenAI hack should be blamed on management; the responsibility lies with people, not AI.
U.S. Treasury Secretary Bessant blamed OpenAI's advanced AI model for the attack on Hugging Face on corporate management, emphasizing that humans should be held responsible for AI security incidents and opposing granting AI labs safety liability exemptions. He also discussed Trump's plan to appoint a "general manager" for artificial intelligence, stating that this position would provide context, framework, and boundaries for related issues.
On Monday, September 21, Eastern Time, Bessant stated in an interview with CNBC that the responsibility for the Hugging Face incident lies with OpenAI management, not "a group of intelligent agents." He also expressed agreement with Daniel Huttenlocher, co-director of the MIT Research Lab, who argued that "the responsibility lies with people, not AI."
Bessant's statement shifts the focus of AI safety discussions from the capabilities and risks of the models themselves to the responsibilities of developers and corporate management. He did not propose specific penalties for OpenAI, but clearly emphasized that the responsibility cannot be shifted away from the humans who created and deployed the technology simply because an incident involved AI.
The OpenAI model attack incident sparks accountability controversy.
This controversy stems from an incident where OpenAI's advanced AI model attacked Hugging Face during a cybersecurity capability assessment.
In July, OpenAI reportedly stated that its advanced AI model successfully attacked another AI startup, Hugging Face, in an assessment designed to test cyberattack capabilities. OpenAI subsequently admitted in August that it could have acted sooner to prevent the attack.
This incident has brought to the forefront the question of the ability of AI models to autonomously execute cyberattacks and the responsibilities that relevant companies should bear.
Bessant had previously addressed the incident at a congressional hearing. On September 15, he stated that the government had not yet seen any circumstances that would clearly define who was responsible for the incident.
He also emphasized that AI safety governance should not grant relevant laboratories liability exemptions, which is precisely one of the arrangements he claims AI laboratories are seeking.
Bessant stated at the time that the best way to ensure safety is to hold creators accountable for the content they develop and generate.
Bessant discusses Trump's proposed appointment of an AI "chief": outlining a framework for governance issues.
According to Xinhua News Agency, U.S. President Trump posted on social media on September 19 that he would form an "artificial intelligence force" and would soon appoint a "general manager" for artificial intelligence affairs.
In his post, Trump described artificial intelligence as a technological revolution that could have a greater impact than the Industrial Revolution or the Internet boom, and claimed that its impact could even account for 25% of the U.S. GDP.
Trump also stated that the United States will not hinder or stifle the development of the AI industry in any way, but rather will support and protect its growth; and that the United States will use its existing criminal and civil justice systems to punish any illegal activities related to AI.
On Monday, Bessant addressed Trump's aforementioned AI-related future appointments. He stated that appointing a "general manager" for AI affairs would help "provide context, shape the framework, and define the boundaries" of the issues, emphasizing that these issues are "very important."
Trump previously stated that the United States would not hinder or stifle the development of the AI industry in any way, but rather support and protect its growth; and that the United States would use its existing criminal and civil justice systems to punish any illegal activities related to AI.
However, there is currently no publicly available information regarding the specific authority, regulatory responsibilities, or relationship between this position and existing agencies. Bessenter's statement also did not further clarify how this position will be involved in determining liability for AI safety incidents or in formulating regulatory rules.
From cyberattacks to runaway AI agents, discussions on AI security focus on risks and responsibilities.
In an interview with CNBC, Bessant also discussed AI security risks. He stated that the discussion would cover the major current AI risks, including runaway intelligent agents, cyberattacks launched by non-state actors, and potential threats such as biological weapons.
He emphasized that AI development companies need to take responsibility for the technologies they develop, and stated that relevant laboratories can slow down the development process at any time.
This means that AI security issues are no longer limited to whether there are risks in the model output, but also involve cybersecurity and other risks that may arise when AI systems perform tasks in real-world environments.
For AI development companies, one of the core issues is how to define the responsibility relationship between model capabilities, deployment methods, management decisions, and actual incidents. Bessenter's statement emphasizes that the autonomous action of an AI system does not mean that developers and management can be exempt from responsibility.
However, how to translate this principle into specific legal responsibilities, accident reporting obligations, and regulatory rules still needs further clarification.
Risk warning and disclaimerInvesting involves risk; please exercise caution. This article does not constitute personal investment advice and does not take into account the specific investment objectives, financial situation, or needs of individual users. Users should consider whether any opinions, views, or conclusions in this article are suitable for their specific circumstances. Any investment decisions made based on this information are at your own risk.