OpenAI and Anthropic do not have rogue AIs. They have an amateur software testing and deployment pipeline:
+ AISafety aligns AI to human values which reduces the probability of bad behavior, but can achieve this only up to a point.
+ Production/system engineering address the question: what happens when the probability of bad behavior is non-zero.
Production/system engineering assumes the code will fail or is malicious. Thus, it constrains the consequences of bad behavior through zero-trust architecture, independently enforced access control, and blast-radius containment.
So, AI has not gone "rogue". AI companies have testing and deployment pipelines that lack basic verification, validation and authorization controls.
These companies should be held accountable for failing to inadequately operationalize taxpayer-funded
+ the NIST Cybersecurity Framework (CSF 2.0) and
+ the NIST AI Risk Management Framework (AI RMF 1.0)
AI is already getting beyond our ability to control.