From the archive

No on SB 1047

A Real Talk About AI Regulation: California's SB 1047

Ladies and gentlemen, today I want to talk about something that's going to change the world: artificial intelligence. But more importantly, I want to talk about how we guide this revolution. California's Senate Bill 1047 is a well-intentioned step, but it's not the leap we need. Let me tell you why, and how we can make it insanely great.

The Good (Yeah, There's Some)

  1. Whistleblower Protection: It seems as though there's some protection for employees to prevent retaliation, although it seems greatly weakened in later drafts of the bill.

  2. Duty of Care: Every industry has one of these. Complex system technology has them, and many of these industry standards are not being embraced by the AI community.

  3. Mitigation Plans: Forcing companies to think before they act. Revolutionary, right?

  4. Off Switch: Having a clearly documented option to disable the system is great, but it's not clear how it would apply to open source.

The Bad (Buckle Up, It's a Bumpy Ride)

  1. One-Size-Fits-All Approach: Seriously? You can't regulate a Tesla the same way you regulate an iPhone. Wake up! These models are different sizes, with different capabilities. Some are run on a complicated cloud setup, some are run on home desktops, some are fully open source. Each one has different threats and remediations. It’s great that startups and academics will be exempted by the size and dollar requirements, but the granularity really ends there . The model is dangerous or not based on the size of the company and the amount of resources they deploy.

  2. Ignoring Real Threats: While we're worrying about hypothetical super AIs, real AI is wreaking havoc on social media. It's like worrying about aliens while your house is on fire.

  3. Ignoring Capabilities: Under chat, the current LLM models do not produce reliable enough output for large amounts of prose. Even under constraining techniques like RAG, the LLM models are still extremely limited in capability and consistency. Trying to maintain that they won't produce the recipe for nuclear weapons or hack the internet misunderstands capability and what much more pedestrian threats exist today. Any reasonable auditor would have to conclude that no safeguards can be placed on models which can be easily jailbroken, and thus no safeguards can be mandated about the output of these machines for a determined attacker.

How to Make This Bill Great

  1. Fix Bug Bounties: Anthropic has one of the best bug bounty programs and the max payout is $15k for jailbreaking an AI. We can measure the effectiveness of bug bounties if responsible disclosure becomes the norm as the price of the bounty meets the price of the market. If you can break our AI, you should be able to buy a house, not a nice dinner. Make it worth the while of the real talent out there. I’m tracking bug bounties of LLMS at https://hackmd.io/yaYNGD8oSYuvm5pRS2lmZw?edit . Join in and help me make it more complete.

  2. Stronger Whistleblower Protection: If an employee has to destroy their long-term career to whistleblow, they must have some financial payout commensurate with the risk.

  3. Type-Specific Regulation: Language models? Focus on the words. Robots? Focus on the actions. Don't mismatch the threat that you are checking for the wrong model. The duty of care should match the type of model, but some things apply to all critical, connected, complex system technology.

  4. Real-World Benchmarks: Stop with the theoretical BS. Let's see how these AIs perform in the real world. ARC-AGI for general skills, sure, but let's get specific. How does it handle a Twitter mob? Can it navigate rush hour without causing a 50-car pileup? If you can't come up with sensible limitations, just do less and focus on social constraints like the ones we've listed above.

  5. When in Doubt, Leave it Out: This is just the first bill, not the last. Rather than trying to build an all-encompassing bill that includes theoretical future threats in 10 years, create a cleaner bill that measures things that a regulator or auditor can easily understand. We already brought up bug bounties, existing capability standards, and existing threats we see in the wild.

The Revolution Starts Now

Ladies and gentlemen, AI isn't just another technological advancement. It's a paradigm shift that will redefine how we live, work, and create. We have a unique opportunity – and responsibility – to shape this future.

California has always been at the forefront of innovation. Now, we must lead in responsible innovation. We need regulation that's as innovative as the technology it governs. Regulation that fosters growth while ensuring safety. Regulation that's visionary yet practical.

Remember, the people who are crazy enough to think they can change the world are the ones who do. Let's be crazy. Let's be bold. Let's craft AI regulation that's worthy of the incredible future we're building.

The future is not something that happens to us. It's something we create. So let's create a future where AI empowers humanity, where innovation and responsibility go hand in hand, and where California continues to show the world what's possible when vision meets execution.

← All writing