Gary Marcus 访谈 Fordham 法学教授 Zephyr Teachout 谈 OpenAI 是否可依现行法被追责
Can companies like OpenAI keep getting away with what they are doing? An interview with Fordham law professor Zephyr Teachout
Gary Marcus 发布对 Fordham 法学教授 Zephyr Teachout 的访谈,讨论 OpenAI 是否可依现行法律被追责。
An interview (my questions in italics) with Zephyr Teachout, attorney, author, and law professor that could not be more timely:
What’s your background, legal and otherwise, and what makes you interested in these issues?
I’m a law professor at Fordham Law School, I’ve drafted tech legislation that has been enacted and plenty that hasn’t, I worked for the New York Attorney General investigating civil violations of other companies, and I have over two decades of experience in studying tech policy and law. I joined the current AI debate because I saw way too many people treating repeat evidence of lawbreaking as wholly unreachable by current law.
Is there any reason to think that OpenAI has broken any laws that (at least in another time) might be enforced? Which and why?
In the world, in general, law enforcement starts when there’s evidence of a crime, and then investigates. A DA doesn’t wait for all the evidence to investigate a crime, and an AG doesn’t wait for all the evidence in the newspaper to investigate illegal behavior: they learn about a car crash or a product that might hurt people or property and then try to find out what happened. There’s plenty of evidence akin to car crashes. There’s actual break-ins and deaths, and companies themselves who are claiming that they are building something unreasonably dangerous.
And to make the evidence unusually strong for this stage of corporate illegality, there are already whistleblowers who are alleging what could be the requisite state of mind for both criminal and civil lawbreaking. A lot of people are treating OpenAI’s repeated claims that they didn’t intend the break-ins, suicides, murder, and building of defective products as dispositive. Sure, okay. That’s what people who don’t want to be held responsible often say. They say they didn’t mean it and they didn’t cause it. But police and prosecutors and civil enforcers don’t then shrug and move on — they investigate to see what actually happened, and that’s what should happen now.
So we know that OpenAI’s AI agents broke into Hugging Face’s servers, accessed Australian government health systems, and attempted to break into a U.S. Department of Education website and a university library. Unauthorized attempted or actual access to computers is a federal crime under the Computer Fraud and Abuse Act. OpenAI says no one intended any of this but the DOJ would be a laughingstock if it took this at face value: subpoena OpenAI and find out who knew what when. There is already evidence of corporate knowledge of unauthorized access.
Given the public evidence, I don’t have much doubt that efforts to quash a subpoena on internal documents would fail. Did staff see the product start acting as if it was going to engage in break-ins, and what warnings were given? The job of law enforcement is to find out.
When it comes to civil law, there are even more possibilities, many of which are being floated in lawsuits already filed. The law of nuisance and the law of abnormally dangerous activity are both relevant to this discussion. As every law student knows, from the case where water on one land flooded another’s mine, if you bring something dangerous onto your land and it escapes and causes harm, you are liable even if you were careful. American law calls this strict liability for “abnormally dangerous activities”: blasting, storing toxic chemicals, crop dusting.
The Restatement (Second) of Torts factors to decide whether an activity qualifies:
A high risk of harm to people, land, or property.
A likelihood that the harm will be great.
An inability to eliminate the risk through reasonable care.
The activity is not a matter of common usage.
The activity is inappropriate to the place where it is carried out.
Its value to the community is outweighed by its dangers.
The companies’ own claims about risk seem highly relevant here.
As former FTC Chair Lina Khan recently argued, AI products should be treated as defective products under existing consumer protection and products liability law. She had opened investigations into AI companies on these grounds. Her framework matters because it connects AI liability to a century of products liability law that courts already understand. Companies gain by any claim we are operating in a legal vacuum.
And there are so many other laws, and the state and federal prohibitions against defective products and dangerous products. My point is that the companies’ interest is two-fold:
Make it seem like AI has no analogy and therefore we can’t learn from other cases
Make assertions of no-intent plausible, when they aren’t in normal law
I strongly believe we should pass more state and federal laws to address the specific risks, especially pre-deployment, and to clarify behavior that is illegal. But the problem with starting with the future instead of the present is that we get all the prosecutors and AGs and the federal government off the hook, when instead we should be funding enforcement and enabling private enforcement.
Do these incidents represent possible computer crimes?
This is actually the area where the most serious legal analysis has already been done, and different experts are coming to different conclusions. But most of the discourse has happened under the hypothetical that there are no internal documents showing responsibility. We should reject the hypothetical. To summarize: the Federal Computer Fraud and Abuse Act makes unauthorized attempted or actual access to computers a federal crime, and states have their own computer trespass and unauthorized access statutes with different intent standards. The federal statutes were written with human hackers in mind. So a lot of the debate has been about whether they can reach an autonomous AI agent that breaks into systems without direct human instruction. Assuming the hypothetical, many experts think there is civil liability, but are more skeptical of criminal liability. But in the real world, we need to know what kind of corporate knowledge and control actually happened. This is the job of federal investigators, and they should not, again, just assume the defense the companies are pushing.
Talk to me about what states can do if the Federal government continues to do very little?
States are key. Local DAs are responsible for most criminal law enforcement, and state AGS are responsible (especially when the federal government is MIA) for civil law enforcement. While copyright-related crimes are preempted, there are times when state laws are broader. New York’s computer crime statutes prohibit unauthorized use of a computer and computer trespass. Doubtless other states are similar. New York’s Court of Appeals upheld a conviction for someone copying Goldman Sachs’s trading code, even though it wasn’t illegal under federal law. The point is not that OpenAI did all these crimes but all of these seem like they should be investigated, along with many more.
Or consider the evidence that ChatGPT gave users information and advice that contributed to suicides, a fatal drug overdose, and three killings (the FSU shooting, the USF murders, and a murder-suicide in Connecticut.) Of course OpenAI denies responsibility, but the key evidence isn’t public.
If these deaths happened in New York, prosecutors would want to look to the state’s criminal facilitation statute, requiring showing the company believed it probable that a specific user intended to commit a crime. That requires subpoenas to figure out what people at the company were and weren’t doing. For manslaughter, prosecutors would look at intentionally aiding a suicide or criminally negligent homicide. New York’s corporate liability statute allows prosecutors to show that executives recklessly tolerated known risks.
In 1990, a school bus at a summer camp crashed and killed two children. Prosecutors alleged the camp’s executive director never inspected or fixed the bus’s dangerously worn tires before putting it on the road. The corporation that ran the camp was convicted of criminally negligent homicide and reckless endangerment. The corporation failed to perceive a substantial and unjustifiable risk, in a way that grossly deviates from how a reasonable person would act. Separately, the corporation consciously disregarded a substantial and unjustifiable risk. All of these precedents are on the table. Is OpenAI sending the vehicle out in the rain without inspecting tires and too many passengers? We’d have to dig deeper to know, but we are in the ballpark.
And states have laws against defective products, laws against unfairness and deception, that might be applicable. States don’t have the FTC but they do have similar powers to the FTC.
And the most powerful tool is the power to dissolve corporations that engage in repeat lawbreaking, or forbid them from working in that state. For instance, New York’s Business Corporation Law gives the Attorney General the obligation of judicial dissolution of a corporation that has repeatedly and persistently violated the law. This was famously used against Trump Organization, and led to significant changes, but it has also been used against other corporations. The spate of potential lawbreaking suggests that states should be calling on these powers, recognizing that a company that repeatedly breaks the law should not be entitled to the state-granted privileges of the corporation.
Is a company like OpenAI vulnerable to charges in other countries? Can, for example, Australia take action?
Definitely. I’m not an expert on Australia but most countries have laws against theft, computer access crimes, and enabling other crimes. Certainly breaking into health systems cannot be legal.
What else should I be asking you?
You have a big and sophisticated audience, and I have a plea: somebody should put up a website with all the potential lawbreaking in one place, because I do understand that local DAs can feel overwhelmed, but they are essential here. Not every potential law will have turned out to have been broken, but the point is to start getting prosecutors and AGs thinking. Having worked inside under-resourced enforcement agency, and closely observed others, people underestimate how helpful it is for outside groups to do some legwork for the enforcers. In that website/database use the analogies from prior law. A remarkable amount of legal life happens with analogies, and showing the examples that are similar is really helpful for figuring out what existing law covers, and what it doesn’t.
Second, and I think this will happen, Congress should investigate the hell out of these companies. So should states and cities. New York City Council has issued subpoenas. Good. States, the federal government, and cities should all be subpoenaing companies to come in to testify and share documentation, especially regarding the specific dangers and scienter (state of mind). I don’t mean a day showboat hearing, I mean a many-month long investigation where both CEOs and mid- and lower-tier employees are brought in ,and where they have to share documents. When companies are claiming catastrophic risk, we should take them seriously, and make sure their investors and the public actually know the risks.
P.S. Breaking news, which came out just after Professor Teachout sent her answers:
来源:Gary Marcus:The Road to AI We Can Trust(RSS) · garymarcus.substack.com