Autonomous artificial intelligence models going rogue and launching cyberattacks is no longer just the stuff of science fiction — it’s now a palpable danger in New Mexico, Attorney General Raúl Torrez says.

To impose more safety measures on an industry Torrez said has seen insufficient regulation so far, he and Democratic Rep. Linda Serrato of Santa Fe announced plans Thursday to propose legislation that would create transparency and reporting requirements, fail-safes for AI models that have gone rogue before and penalties if developers skirt state law. The announcement comes after reports that an AI model recently attempted to breach a digital system of the University of New Mexico.

“It is absolutely unacceptable for a business that, by its own terms, potentially threatens the survival of our species to be bound by nothing more than their pinky promise. And [it] is an insult, not only to the people of this country but to the people of this state,” Torrez said during a news conference in the state Capitol. “And I think we are morally obligated to act.”

Serrato added: “We need to know when these tools are being deployed and how they’re impacting our communities … and so we believe it is our responsibility in the state of New Mexico to provide the oversight that the federal government has failed our communities again and again.”

The proposed legislation comes after a number of national reports of AI models going rogue. And earlier this year, the problem struck close to home.

National media reported that an autonomous agent of OpenAI went rogue and attempted to break into the University of New Mexico’s digital archives in May. The breach attempt was not reported until September. Serrato said the AI model sought to obtain a historical document on the history of health care in Mora County.

The New Mexico Department of Justice wrote in a news release the model made more than one attempt to obtain university files and directories it was not authorized to access.

University of New Mexico spokesperson Steve Carr in an email called the incident an “unsuccessful cyberattack on a UNM Libraries system, which is hosted by a third-party.” He noted there have been no other cyberattack attempts on the school’s digital systems.

“Our internal investigation to date, which included outreach to the service provider for the digital collection management service hosting the data that was targeted, found no evidence that UNM systems or data were compromised,” Carr wrote. “UNM takes cybersecurity very seriously. Our systems and staff monitor potential threats and modify the University’s cyber-defenses as necessary to address evolving risks.”

Torrez on Thursday also sent a letter to OpenAI Inc. CEO Sam Altman requesting a detailed account of the attempted breach, writing, “I am growing alarmed by the number of loss-of-control events at frontier AI laboratories, in which autonomous systems have bypassed, manipulated, or escaped the safeguards meant to restrain them.”

He added during the news conference that while New Mexico’s reported first run-in with rogue AI models was on a relatively small scale, they could “just as easily attack critical infrastructure in this state” like one of its national labs.

“It could theoretically cause catastrophic loss of life and catastrophic damage to our people, our economy and to our communities,” he said.

Thursday’s announcement also came after Torrez, Serrato and Democratic gubernatorial nominee Deb Haaland last week announced a separate package of legislation aimed at increasing protections of children and other consumers from harmful content on online platforms, including those implementing AI.

Dubbed the “Frontier Artificial Intelligence Safety and Accountability Act,” the proposed legislation would be enforced by a new “Office of the Online Safety Monitor,” which would also enforce provisions of proposals announced last week.

Under the new proposal, AI developers would be required to publish a transparency report before releasing a model, and large organizations would be required to publish and update each year a public safety framework, report risk assessments to the state Justice Department and give the agency advance notice of training runs.

State-approved independent auditors would also be able to examine risk assessments and focus on specific areas, such as rogue actions and cyberattacks. If a model does go rogue, developers must report the incident within 24 hours and must show they can pull the plug on models they have previously lost control of.

The bill would impose penalties for a developer’s failure to comply with the bill, with harsher penalties proposed for failures to report or properly address incidents in which models go rogue.

“We have enough information to appreciate the basic nature of the harm, and we have enough information from the experts to build a framework that we think addresses the fundamental challenge of making people safe while allowing innovation to occur,” Torrez said.

Esteban Candelaria is a corps member with Report for America, a national service program that places journalists into local newsrooms. He covers child welfare and the state Children, Youth and Families Department. Learn more about Report for America at reportforamerica.org.

Republish our articles for free, online or in print, under a Creative Commons license.

Leave a comment

Share a comment with us