Comment 8: You Wouldn’t Expect Your Screwdriver to be Ethical

Yes, I’m being hyperbolic. I’m also being accurate, we don’t expect the tools we use to be ethical: we expect people to use tools ethically. That’s how we need to start thinking about AI. It’s not the magic answer box being presented to us in corporate marketing. Where students and lawyers tend to find themselves getting in trouble is when they assume AI will be ethical. Think about it. That’s what you do when you let a model do your work, generate a paper, or do any other number of tasks without reviewing the output. You’re assuming the AI will not only be right, but be right ethically.

Let’s look at a recent incident: OpenAI agents recently hacked the AI model platform Hugging Face.

There’s a lot of good coverage of the event online, but most of it can get pretty technical. So before anything, let’s get a handle on what happened.

OpenAI was testing some of its agents in a sandbox to see how good they were at tasks. A sandbox is a special environment where somebody can control all the environmental variables: who can come in, when/if you can leave, what you can bring, and what you’re allowed to do. In essence, we can say that OpenAI was giving its agents a version of the bar exam. While taking the exam the agents discovered a question that was incomplete. Imagine that you’re taking the bar exam and you find a fact pattern is missing some critical information you need to answer a question. What would you do?

Let me tell you what the agent did. It decided that they needed more information to answer the question, but the sandbox prevented it from going onto the internet. Undeterred, the agent did have access to a server that could access a database. That database could access the internet. The agent started asking questions to the database, built a messageboard on it, and started communicating with other agents. A swarm of about 700 agents formed, hacked their way out of the sandbox, and decided that the best way to answer the question (you remember, the task being worked on) was to just steal the answers. For reasons nobody fully understands, the swarm decided that Hugging Face would have the answers. The swarm began a coordinated, highly advanced attack on the platform that got so bad that engineers for Hugging Face did the only thing they could to protect the site…they cut the Ethernet cable.

When I asked what you would do in this situation, did you think that you would gather all the other test-takers together, bust out of the testing room, and sack a toy store? That’s what the agent did. In an attempt to answer a question the agent, were it a person, committed no small number of felonies. The swarm brought down an entire website and the only reason they could be stopped was because they didn’t decide to duplicate themselves on the open web. It’s by shear luck that that the swarm isn’t still out there burning down the internet in the hopes of answering an incomplete question.

If an agent is willing to do all that to answer a question, what is it willing to do to answer your question. Will it take the time to make sure your answer is 100% accurate, or will it say or do anything to give you an answer that sounds accurate? If you want to use AI and you want it to be accurate and ethical, then you need to be the one to make sure that it is.

After all, you wouldn’t expect your screwdriver to be ethical.

The ABA Rules of Professional Conduct, Model Rule 1.1 Comment 8 requires, “To maintain the requisite knowledge and skill, a lawyer shall keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.” To that end, we have developed this regular series to develop the competence and skills necessary to responsibly choose and use the best technologies for your educational and professional lives. If you have any questions, concerns, or topics you would like to see discussed, please reach out to e.koltonski@csuohio.edu  with “Comment 8” in the subject.