The Real Question

I think that Fareed Zakaria’s Washington Post column identifies a real problem but presents a solution that is far too complex and, indeed, misses the nature of the regulatory problem:

The central AI problem is not consciousness; it is agency. A system need not feel anger, ambition or fear to cause harm. It needs only a goal, enough intelligence to pursue it and enough access to the world to act. AI’s are not “going rogue”; they are trying to succeed any which way they can.

This is a systemic problem that we cannot leave to the good graces of private companies. When thinking about regulations, we should focus centrally on how much autonomy we give these systems. A chatbot that answers a question poses one set of risks. An agent that can browse the internet, execute code, obtain credentials, move money or operate critical infrastructure poses another. The principle I would propose is simple: Autonomy should expand only as our ability to monitor and control it expands.

I think the solution is simultaneously simpler and older than Mr. Zakaria imagines: strict liability that attaches both jointly and severally to the model developer, API developer, the application developer, and the corporate deployer. If that strategy were used, insurance would become an important part of AI governance.

If an AI system causes legally recognizable harm, the injured party need not establish negligence, recklessness, intent, or a defect in the model. The plaintiff must establish the harm, causation, and a legally defined connection between that harm and the entity that supplied or deployed the AI service. An insurer asked to cover an autonomous AI service would want to know about sandboxing, permissions, audit trails, model evaluations, financial authority, network access, kill switches, and incident history. A poorly controlled autonomous agent would become expensive or impossible to insure.

When liability attaches both jointly and severally the plaintiff need not identify the source of harm specifically. Only that harm was done and AI was part of the chain that produced it.

Joint and several liability is important here. The injured party should not bear the burden of determining which participant in an opaque technological supply chain was ultimately responsible for the behavior that caused the harm. Let the parties that designed, supplied, integrated, and deployed the system allocate that responsibility among themselves through contracts, indemnification, contribution, and insurance.

Zakaria’s safeguards would not disappear under strict liability. They would become the things an AI developer or deployer must demonstrate in order to obtain affordable insurance.

1 comment… add one
  • steve Link

    In theory sounds good. In reality you are going after companies with billions of dollars with strong political connections. The finance people made billions, then destroyed the economies of many nations in the 2000s and almost none faced any real consequences. They squealed about not getting bonuses. Same will happen here.

    Steve

Leave a Comment