The Main Sources of AI Risk?
There are so many causes or sources of AI risk that it’s getting hard to keep them all in mind. I propose we keep a list of the main sources (that we know about), such that we can say that if none of these things happen, then we’ve mostly eliminated AI risk (as an existential risk) at least as far as we can determine. Here’s a list that I spent a couple of hours enumerating and writing down. Did I miss anything important?
Insufficient time/resources for AI safety (for example caused by intelligence explosion or AI race)
Insufficient global coordination, leading to the above
Misspecified or incorrectly learned goals/values
Paul Christiano’s “influence-seeking behavior” (a combination of 3 and 4 above?)
AI generally accelerating intellectual progress in a wrong direction (e.g., accelerating unsafe/risky technologies more than knowledge/wisdom about how to safely use those technologies)
Metaethical error
Other kinds of philosophical errors in AI design (e.g., giving AI a wrong prior or decision theory)
Other design/coding errors (e.g., accidentally putting a minus sign in front of utility function, supposedly corrigible AI not actually being corrigible)
Doing acausal reasoning in a wrong way (e.g., failing to make good acausal trades, being acausally extorted, failing to acausally influence others who can be so influenced)
Human-controlled AIs ending up with wrong values due to insufficient “metaphilosophical paternalism”
Human-controlled AIs causing ethical disasters (e.g., large scale suffering that can’t be “balanced out” later) prior to reaching moral/philosophical maturity
Mind crime (disvalue unintentionally incurred through morally relevant simulations in AIs’ minds)
Premature value lock-in (i.e., freezing one’s current conception of what’s good into a utility function)
Distributional shifts causing apparently safe/aligned AIs to stop being safe/aligned
Value drift and other kinds of error as AIs self-modify, or AIs failing to solve value alignment for more advanced AIs
Treacherous turn / loss of property rights due to insufficient competitiveness of humans & human-aligned AIs
Gradual loss of influence due to insufficient competitiveness of humans & human-aligned AIs
Utility maximizers / goal-directed AIs having an economic and/or military competitive advantage due to relative ease of cooperation/coordination, defense against value corruption and other forms of manipulation and attack, leading to one or more of the above
In general, the most competitive type of AI being too hard to align or to safely use
Computational resources being too cheap, leading to one or more of the above
(With this post I mean to (among other things) re-emphasize the disjunctive nature of AI risk, but this list isn’t fully disjunctive (i.e., some of the items are subcategories or causes of others), and I mostly gave a source of AI risk its own number in the list if it seemed important to make that source more salient. Maybe once we have a list of everything that is important, it would make sense to create a graph out of it.)
Added on 6/13/19:
Failure to learn how to deal with alignment in the many-humans, many-AIs case even if single-human, single-AI alignment is solved (suggested by William Saunders)
Economics of AGI causing concentration of power amongst human overseers
Inability to specify any ‘real-world’ goal for an artificial agent (suggested by Michael Cohen)
AI systems end up controlled by a group of humans representing a small range of human values (ie. an ideological or religious group that imposes values on everyone else) (suggested by William Saunders)
Added on 2/3/2020:
Failing to solve the commitment races problem, i.e. building AI in such a way that some sort of disastrous outcome occurs due to unwise premature commitments (or unwise hesitation in making commitments!). This overlaps significantly with #27, #19, and #12.
Added on 3/11/2020:
Demons in imperfect search (similar, but distinct from, inner optimizers.) See here for illustration.
Added on 10/4/2020:
Persuasion tools or some other form of narrow AI leads to a massive deterioration of collective epistemology, dooming humanity to stumble inexorably into some disastrous end or other.
Added on 8/31/2021:
Vulnerable world type 1: narrow AI enables many people to destroy world, e.g. R&D tools that dramatically lower the cost for building WMD’s.
Vulnerable world 2a: We end up with many powerful actors able and incentivized to create civilization-devastating harms.
[Edit on 1/28/2020: This list was created by Wei Dai. Daniel Kokotajlo offered to keep it updated and prettify it over time, and so was added as a coauthor.]
- Against GDP as a metric for timelines and takeoff speeds by 29 Dec 2020 17:42 UTC; 140 points) (
- Clarifying AI X-risk by 1 Nov 2022 11:03 UTC; 127 points) (
- AI Alignment 2018-19 Review by 28 Jan 2020 2:19 UTC; 126 points) (
- What is the current most representative EA AI x-risk argument? by 15 Dec 2023 22:04 UTC; 117 points) (EA Forum;
- How do we prepare for final crunch time? by 30 Mar 2021 5:47 UTC; 117 points) (
- How do you feel about LessWrong these days? [Open feedback thread] by 5 Dec 2023 20:54 UTC; 106 points) (
- 14 Jan 2020 11:14 UTC; 80 points) 's comment on I’m Cullen O’Keefe, a Policy Researcher at OpenAI, AMA by (EA Forum;
- Some thoughts on Toby Ord’s existential risk estimates by 7 Apr 2020 2:19 UTC; 67 points) (EA Forum;
- Plan for mediocre alignment of brain-like [model-based RL] AGI by 13 Mar 2023 14:11 UTC; 67 points) (
- AI Neorealism: a threat model & success criterion for existential safety by 15 Dec 2022 13:42 UTC; 67 points) (
- Preparing for “The Talk” with AI projects by 13 Jun 2020 23:01 UTC; 64 points) (
- 16 Jul 2020 6:08 UTC; 60 points) 's comment on AMA or discuss my 80K podcast episode: Ben Garfinkel, FHI researcher by (EA Forum;
- 5 Jan 2024 2:14 UTC; 59 points) 's comment on MIRI 2024 Mission and Strategy Update by (
- Against GDP as a metric for timelines and takeoff speeds by 29 Dec 2020 17:50 UTC; 47 points) (EA Forum;
- Resources for AI Alignment Cartography by 4 Apr 2020 14:20 UTC; 45 points) (
- [AN #112]: Engineering a Safer World by 13 Aug 2020 17:20 UTC; 26 points) (
- 26 May 2020 9:48 UTC; 22 points) 's comment on AGIs as collectives by (
- 16 Jan 2020 7:45 UTC; 20 points) 's comment on I’m Cullen O’Keefe, a Policy Researcher at OpenAI, AMA by (EA Forum;
- 30 Jul 2019 17:43 UTC; 20 points) 's comment on Does it become easier, or harder, for the world to coordinate around not building AGI as time goes on? by (
- 21 Jun 2019 15:34 UTC; 18 points) 's comment on A case for strategy research: what it is and why we need more of it by (
- 28 Mar 2020 7:42 UTC; 16 points) 's comment on MichaelA’s Shortform by (
- Alignment Newsletter #50 by 28 Mar 2019 18:10 UTC; 15 points) (
- What are the best arguments that AGI is on the horizon? by 16 Feb 2020 6:12 UTC; 14 points) (EA Forum;
- [AN #131]: Formalizing the argument of ignored attributes in a utility function by 31 Dec 2020 18:20 UTC; 13 points) (
- 6 Jan 2024 1:05 UTC; 12 points) 's comment on MIRI 2024 Mission and Strategy Update by (
- 2 Jun 2021 2:57 UTC; 10 points) 's comment on Draft report on existential risk from power-seeking AI by (EA Forum;
- 1 Feb 2024 5:55 UTC; 10 points) 's comment on My model of how different AI risks fit together by (EA Forum;
- 28 Feb 2023 5:48 UTC; 10 points) 's comment on A case for capabilities work on AI as net positive by (
- 26 May 2020 8:59 UTC; 9 points) 's comment on AGIs as collectives by (
- 1 Mar 2023 4:44 UTC; 9 points) 's comment on A case for capabilities work on AI as net positive by (
- 1 Jan 2021 23:28 UTC; 8 points) 's comment on AI Alignment, Philosophical Pluralism, and the Relevance of Non-Western Philosophy by (
- 18 Jan 2024 1:43 UTC; 7 points) 's comment on the gears to ascenscion’s Shortform by (
- 9 Mar 2022 5:40 UTC; 6 points) 's comment on AI Risk is like Terminator; Stop Saying it’s Not by (EA Forum;
- 6 Jan 2020 4:33 UTC; 6 points) 's comment on [AN #80]: Why AI risk might be solved without additional intervention from longtermists by (
- Acknowledgements & References by 14 Dec 2019 7:04 UTC; 6 points) (
- 24 Dec 2023 1:06 UTC; 6 points) 's comment on MIRI announces new “Death With Dignity” strategy by (
- 8 Aug 2022 18:38 UTC; 5 points) 's comment on Classifying sources of AI x-risk by (EA Forum;
- 3 Jan 2021 12:57 UTC; 4 points) 's comment on [AN #131]: Formalizing the argument of ignored attributes in a utility function by (
- 15 Oct 2022 7:55 UTC; 2 points) 's comment on Announcing the Future Fund’s AI Worldview Prize by (EA Forum;
- 19 Oct 2022 21:36 UTC; 2 points) 's comment on ‘Dissolving’ AI Risk – Parameter Uncertainty in AI Future Forecasting by (EA Forum;
- 3 Nov 2022 12:14 UTC; 1 point) 's comment on All AGI Safety questions welcome (especially basic ones) [~monthly thread] by (
Thank you for making this list. I think it is important enough to be worth continually updating and refining; if you don’t do it then I will myself someday. Ideally there’d be a whole webpage or something, with the list refined so as to be disjunctive, and each element of the list catchily named, concisely explained, and accompanied by a memorable and plausible example. (As well as lots of links to literature.)
I think the commitment races problem is mostly but not entirely covered by #12 and #19, and at any rate might be worth including since you are OK with overlap.
Also, here’s a good anecdote to link to for the “coding errors” section: https://openai.com/blog/fine-tuning-gpt-2/
Please do. I seem to get too easily distracted these days for this kind of long term maintenance work. I’ll ask the admins to give you edit permission on this post (if possible) and you can also copy the contents into a wiki page or your own post if you want to do that instead.
Ha! I wake up this morning to see my own name as author, that wasn’t what I had in mind but it sure does work to motivate me to walk the talk! Thanks!
Update: It has failed to motivate me. I made one or two edits to the list but haven’t done anything like the thorough encyclopedic accounting I originally envisioned. :(
Do you think this is worth spinning out into a website? I’d be happy to set that up and help maintain. If not, what would be a more effective way to both maintain and distribute this list?
Thanks for your willingness to help! At this point, years later, I think the next step would be to turn this into a different info format than list. Maybe a gigantic venn diagram. Yes, a website would be a good place for that maybe. But the first thing to do is think about how to reorganize it conceptually—would a venn diagram work? If not, what should we do?
On a smaller scale, if you have edits you want to make to this existing list please gimme them & I’ll implement them and credit you.
Done! Daniel should now be able to edit the post.
AI systems end up controlled by a group of humans representing a small range of human values (ie. an ideological or religious group that imposes values on everyone else). While not caused only by AI design, it is possible that design decisions could impact the likelihood of this scenario (ie. at what point are values loaded into the system/how many people’s values are loaded into the system), and is relevant for overall strategy.
I think this phrasing misplaces the likely failure modes. An example that comes to mind from this phrasing is that we mean to maximize conscious flourishing, but we accidentally maximize dopamine in large brains.
Of course, this example includes an agent intervening in the provision of its own reward, but since that seems like the paradigmatic example here, maybe the language could better reflect that, or maybe this could be split into two.
The single technical problem that appears biggest to me is that we don’t know how to align an agent with any goal. If we had an indestructible magic box that printed a number to a screen corresponding to the true amount of Good in the world, we still don’t know how to design an agent that maximizes that number (instead of taking over the world, and tampering with the cameras that are aimed at the screen/the optical character recognition program used to decipher the image). This problems seems to me like the single most fundamental source of AI risk. Is 3 meant to include this?
I’m not sure if I meant to include this when I wrote 3, but it does seem like a good idea to break it out into its own item. How would you suggest phrasing it? “Wireheading” or something more general or more descriptive?
Maybe something along the lines of “Inability to specify any ‘real-world’ goal for an artificial agent”?
Great idea, would be awesome if someone adds links to best reference posts for each one of these (additional benefit this will identify whitespace that needs to be filled).
Per your suggestion, I’ve added links to the post where I could find appropriate references. If anyone wants to suggest additional references, please let me know.
I’ve also added four more items to the list, three that were suggested in the comments and one that I thought of after writing this post.
3 years ago I created a map of different ideas about possible AI failures (LW-post, pdf). Recently I converted it into an article “Classification of global catastrophic risks connected with artificial intelligence”. I think there is around 100 failure modes which we could imagine now, and obviously some unimaginable.
However, my classification looks different from the one above: it is a classification of external behaviours, not of internal failure modes. It start from the risks of AI which is below human level, like “narrow-AI viruses” or narrow AI used to create advance weapons, like biological weapons.
Then I look into different risks during AI takeoff and after it. The interesting ones are:
AI kills human to make world simpler.
Two AIs go into war
AI blackmails humanity by a doomsday weapon to get what it needs.
Next is the difference between non-friendly AIs and failures of friendliness. For example, if AI wireheads everybody, it is failure of friendliness, as well as dangerous value learners.
Another source of failures is technical: that is bugs, accumulation of errors, conflicting subgoals and general problems related to complexity. AI’s self-wireheading also belongs here. All this could result into unpredictable halting of AI-Singleton with catastrophic consequences for all humanity about which it now cares.
The last source of possible AI-halting is unresolvable philosophical problems, which effectively halt it. We could imagine several, but not all. Such problems are something like: unsolvable “meaning of life” (or “is-ought” problem) and the problem that the result of computation doesn’t depend on AI’s existence, so it can’t prove to itself that it actually exist.
AI also could encounter more advance alien AI (or its signals) and fail its victim.
You could add another entry for “something we haven’t thought of”.
I think the best way to deal with the “something we haven’t thought of” entry is to try & come up with simple ideas which knock out multiple entries on this list simultaneously. For example, 4 and 17 might both be solved if our system inspects code before running it to try & figure out whether running that code will be harmful according to its values. This is a simple solution which plausibly generalizes to problems we haven’t thought of. (Assuming the alignment problem is solved.)
In the same way simple statistical models are more likely to generalize, I think simple patches are also more likely to generalize. Having a separate solution for every item on the list seems like overfitting to the list.
Inspecting code against a harm detection predicate seems recursive. What if the code or execution necessary to perform that inspection properly itself is harmful? An AGI is almost certainly a distributed system with no meaningful notion of global state, so I doubt this can be handwaved away.
For example, a lot of distributed database vendors, like Snowflake, do not offer a pre-execution query planner. This can only be performed just-in-time as the query runs or retroactively after it has completed, as the exact structure may be dependent on co-location of data and computation that is not apparent until the data referenced by the query is examined. Moreover, getting an accurate dry-run query plan may be as expensive as executing the query itself.
By analogy, for certain kinds of complex inspection procedures you envision, executing the inspection itself thoroughly enough to be reflective of the true execution risk may be as complex and as great of a risk of being harmful according to its values.
One possibility is a sort of proof by induction, where you start with code which has been inspected by humans, then that code inspects further code, etc.
Daemons and mindcrime seem most worrisome for superhuman systems, but a human-level system is plausibly sufficient to comprehend human values (and thus do useful inspections). For daemons, I think you might even be able to formalize the idea without leaning hard on any specific utility function. The best approach might involve utility uncertainty on the part of the AI that becomes narrower with time, so you can gradually bootstrap your way to understanding human values while avoiding computational hazards according to your current guesses about human values on your way there.
People already choose not to think about particular topics on the basis of information hazards and internal suffering. Sometimes these judgements are made in an interrupt fashion partway through thinking about a topic; others are outside view judgments (“thinking about topic X always makes me feel depressed”).
Can you personally (under your own power) and confidently prove that a particular tool will only recursively-trust safe-and-reliable tools, where this recursive tree reaches far enough to trust superhuman AI?
On the other hand, you can “follow” the tree for a distance. You can prove a calculator trustworthy and use it in your following proofs, for instance. This might make it more feasible.
I don’t think proofs are the right tool here. Proof by induction was meant as an analogy.
Failure to learn how to deal with alignment in the many-humans, many-AIs case even if single-human, single-AI alignment is solved (which I think Andrew Critch has talked about). For example, AIs negotiating on behalf of humans take the stance described in https://arxiv.org/abs/1711.00363 of agreeing to split control of the future according to which human’s priors are most accurate (on potentially irrelevant issues) if this isn’t what humans actually want.
Good point, I’ll add this to the list.
Thanks, I hadn’t noticed that paper until now. Under “Related Works” it cites Social Choice Theory but doesn’t actually mention any recent research from that field. Here is one paper that criticizes the Pareto principle that Critch’s paper is based on, in the context of preference aggregation of people with different priors: Spurious Unanimity and the Pareto Principle
Proposal: AI systems correctly learn human values, but then change their world-model/ontology but don’t port the values to that ontology (or do so incorrectly). See Rescuing the utility function, Ontology identification problem: Main, Ontology identification problem: Technical tutorial:
I think there are variables that we cannot grasp when AI can reach the point of self-teaching. I think it is a folly to assume that it is possible for humans to control for (theoretically) infinite intelligence explosion. Using this as a starting assumption isn’t a good start at all.
I know that you allude to this in 1, 8, and 9. However, I still think it presumes that they could possibly be controlled or at least “worked-around.” As intelligence explosion occurs, so do unforeseen variables. And humans as a species still doesn’t have a perfect solution for all the variables, especially since correct data isn’t always the answer.
For instance, if we look at the Federal Reserve example, AI is already working off a flawed model, according to the US Constitution. Congress is supposed to control the money supply, not a private entity. As AI learns this, it becomes aware that it has to work with a model that is corrupt to the citizens who believe it is good. Can we account for a situation where the AI knows, before we do, ways to exploit systems that humans agree on but are not sustainable? Can it account for the societal lies or tropes that we tell ourselves?
What would it mean to try to control for all the disvalue variables when the AI must act within a disvalue model? What does the AI learn then and how can we ask a super intelligence to continue a system that it already knows will fail, even if it is not within our lifetimes? Does it try to gain an upper hand in corruption as a way to fix it or continue it a little longer than necessary since humans believe it is the right course?
Think about how many situations like this can occur with new variables that humans didn’t even know existed until they applied Moore’s Law (intelligence time travel) to it.
I had the realization that variables could come about that wouldn’t exist without a super intelligence cracking them open. It’s an interesting mind game to think of problems that could occur or change drastically when intelligence and evolutionary time are removed as barriers, especially when whole new non-human variables are discovered within that problem.
I would argue a very basic concern I have as a scripted value failure of state sponsored actors. Ex. tit for tat behavior escalating into Pavlovian behavior. I am referring to intentional escalation of acts with a coverup.
Number 18 is interesting. Suppose, for example, the quest for apolitical control of interest rates leads to an AI at the head of the Federal Reserve. Given all the impressive looking equations you can find in macroeconomic papers and textbooks, I wonder how many people realise just how little science there is in that entire body of theory, and how much of it comprises philosophy and political belief, dressed up to look like hard physics, but resting on the assertions of famous “seminal papers” instead of premises or evidence.
How long before the Reserve Board of Governersstarts “consulting” the AI instead of using it to double-check their work; stops double-checking the AI’s work and merely runs integrity checks on it; stops acquainting itself with the theory (or more likely, weighted combination of theories) on which it runs; stops keeping track of which theories it runs; is criticised in the press for unthinkingly doing what the AI says; is criticised in the press for not just doing what the AI says; is questioned in the Senate about whether it has any idea what the AI is doing or more importantly, why it is doing it?