Elektrine lite

← Feed

@zackwhittaker@mastodon.social

Post #4373641

2026-08-04 11:18 UTC

RE: https://mastodon.social/@zackwhittaker/117033323332487017 If there's one thing I've learned from publishing this story is that there is a very, very, very wide chasm between what the law says about all this... and what people *think* the law says and/or *should* say.

Replies (5)

  • @zackwhittaker@mastodon.social From the article: The problem with the OpenAI and Anthropic hacks is that the hacker was not a human, but an LLM. This makes no sense. The days of phone phreaking where you could train yourself to whistle the correct tones to bypass security mechanisms are decades past. These days all hacks involve tools. Some are quite sophisticated and will try a bunch of different attach techniques. LLMs are different in implementation technology, but not in effect. If I point Metasploit at your system, I don't get to say 'it wasn't me, an autonomous agent did it!'. I can't speak to the US Law, but the Computer Misuse Act in the UK was explicitly written to not cover specific tools nor exploit techniques, because it wasn't intended to be updated every week as attackers came up with new attacks (I am not a lawyer, but accreditation for a computer science degree requires courses on the relevant bits of law for computer professionals). It requires the court to establish two things: Was a computer system accessed without authorisation?Was there any malicious intent? The first of these is clear: yes, unless HuggingFace was lying. They have logs that can demonstrate this. The second is harder and there are some blurry lines between. The extremes are clear, but there's a big blob of negligence in the middle. Even without explicit intent, enabling a dangerous system without sufficient safeguards may be enough. A court would probably spend a lot of time arguing this. The fact that their 'safeguards' were not in the harness for the LLM and were just parts of the prompt would be something a competent prosecutor would bring up and would call expert witnesses to say that this kind of safeguard cannot be robust. And that's where the novel legal territory is. It has nothing to do with whether LLMs are real boys, it's all about how much you can claim that something is an accident when you connect a random text generator to a machine that runs whatever it produces as a script. And that comes down to expectations of professional standards and is hard to be confident of because a jury will be relying on reasoning by analogy to understand what's happening. But, even without proving intent, either OpenAI or the employees responsible for the system would be potentially liable for up to twelve months in prison and a fine with no statutory limit.

    Open ##4374200

  • @NMBA@mstdn.ca 2026-08-04 11:53

    @zackwhittaker@mastodon.social The law has been paid to forget they are supposed to serve the people in a democracy.

    Open ##4374251

  • @kimlockhartga@beige.party 2026-08-04 11:26

    @zackwhittaker@mastodon.social Lawyers are going to have a time sorting out intellectual property law and copyright law. We are in new territory.

    Open ##4495374

  • @Allkinds@mastodon.social 2026-08-04 12:33

    @zackwhittaker@mastodon.social If you turn turn loose from your yard, you’re a vicious dog and it attacked somebody. You are responsible. Why would it be any different to turn loose your AI on the Internet?

    Open ##4495380

  • @troy_frizzell@mstdn.social 2026-08-04 12:50

    @zackwhittaker@mastodon.social I'm surprised that lawyers would claim that a clear and easily understood issue is actually quite murky and complicated. So complicated that many billable hours will be needed. Super credible.

    Open ##4495388