Elektrine lite

← Feed

@zackwhittaker@mastodon.social

Post #4363313

2026-08-03 19:53 UTC

After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb@infosec.exchange and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it's really complicated; one called it "uncharted territory." Read more: https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/ Bypass for ad-blockers: https://web.archive.org/web/20260803194912/https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/

Replies (6)

  • @jaark@infosec.exchange 2026-08-03 20:03

    @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange I don't see why i's a tricky question. An LLM is just a piece of software that the operator does not fully understand and failed to configure appropriately. If I used a traditional vulnerability scanner (a tool that I sorta but do not completely know exactly what it's doing) and I make a mistake and it interferes with another person's system, I am clearly responsible. The same should lie with the operator(s) of an LLM.

    Open ##4363312

  • @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange Autonomous AI Agent is an oxymoron. Someone controls it That is who you sue.

    Open ##4365133

  • @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange There is no agency in an LLM. The authors, corporation, users are responsible. Not sure why that's difficult to understand. Nail those fuckers to the wall.

    Open ##4373915

  • @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange I've build a robot called MR.Stabby Stabby that went on a rampage. Mr Stabby Stabby is really good at stabbing. My lawyer says it's really complicated and a new ground to cover.

    Open ##4383793

  • Thank you both for writing this article. Well researched. Personally I think it is plain and simple. The person or company who prompted the LLM agent(s) is responsible for it's actions. A computersysteem can in no way be held accountable. Like a car is not accountable. The driver is the one that has to show up in court and who will experience the consequences. @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange

    Open ##4495397

  • @jwi@aus.social 2026-08-03 21:10

    @zackwhittaker@mastodon.social @lorenzofb@infosec.exchange There models to hold companies criminaly liable in other jurisdictions. Under the Australian, which has its flaws, companies can be criminally prosecuted for many offences. My understanding is subsequent to a conviction directors can be held personally liable, unless the responsibility can be pinned elsewhere. One key element is the law needs to be technology neutral. However, I doubt the corporate protection policies of the US would make this difficult. But then the US Supreme Court did rule companies are people in regards to political donations.

    Open ##4495402