Limitations in existing regulatory mechanisms when applied to attacks by AI agents
Juan Jeronimo Manriquez, Tomás Cifuentes Clavijo
Current reporting mechanisms with investigative or regulatory capabilities have deficiencies that make reporting any autonomous AI agent related incidents to date —including the Hugging Face and DSEwiki incidents— infeasible for third parties. This conclusion was reached after conducting an investigation into the two main western AI related legal regimes, with California's SB 53 and the EU’s AI Act being examined, locating three main fault points in these systems. These systems are confidential or do not publish a public record; and fail either by not accepting reports from non-providers, or by having a threshold for what qualifies as an incident that disqualifies the incidents that have already happened. An exploration of the existing literature related to these incidents corroborated that these holes are real and significant. Two main artifacts were created. A complementary website that helps visualize where these systems fail, and a list of proposals that would amend the systems and strengthen them against future attacks carried out by AI agents.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Limitations in existing regulatory mechanisms when applied to attacks by AI agents
},
author={
Juan Jeronimo Manriquez, Tomás Cifuentes Clavijo
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


