Elektrine lite

← Feed

@DaveMWilburn@infosec.exchange

Post #4416466

2026-08-06 11:52 UTC

@flyingpenguin@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange In both of those examples, the statutes' threshold for liability is something other than criminal intent (e.g., negligence) or where the law explicitly requires a profession (e.g., financial advisors) to abide by certain standards, and at least one of those cases is civil rather than criminal. But that's not what the CFAA says. To the best of my knowledge, there's no statute that requires software firms, AI or otherwise, to adhere to certain standards of safety and that creates criminal or civil liability for negligence. And when it comes to holding these bastards accountable for their harmful activity, that's a problem.

Replies (1)

  • @DaveMWilburn@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange uh oh. we agree. that's not supposed to happen, is it? this reminds me of the Grover Shoe Factory again and how states led the way. "No statute puts safety standards on software firms with liability attached" is now only true of the US federal code. EU Cyber Resilience Act is exactly that statute, security requirements as the condition of market access, with their revised Product Liability Directive making software defects strict liability. California and New York already put safety-framework and incident-reporting duties on frontier labs, penalties attached. ye'old steam boilers were same: Massachusetts first, industry code second, federal never. now Meta making it three labs with the same dumb "test" incident means accident has become industry practice, which is exactly what supervision law regulates.

    Open ##4416464