Post #4363312
2026-08-03 20:03 UTC
@zackwhittaker@mastodon.social @lorenzofb@infosec.exchange I don't see why i's a tricky question. An LLM is just a piece of software that the operator does not fully understand and failed to configure appropriately.
If I used a traditional vulnerability scanner (a tool that I sorta but do not completely know exactly what it's doing) and I make a mistake and it interferes with another person's system, I am clearly responsible. The same should lie with the operator(s) of an LLM.
Replies (2)
-
@mzedp@plasmatrap.com 2026-08-03 21:59
@jaark@infosec.exchange @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange Its only tricky because they can afford expensive lawyers and preferential court treatment.
-
@EricLawton@kolektiva.social 2026-08-04 13:38
@jaark@infosec.exchange Exactly. The corporation running the software is liable. If they didn't intend to break in, it's negligence, possibly criminal. They're floating all these "what if it's an agent" trial balloons for publicity. @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange