The China Mail - When rogue AI launches a cyberattack, who is legally responsible?

USD -
AED 3.672502
AFN 66.000029
ALL 82.130758
AMD 361.809635
ANG 1.790365
AOA 917.000284
ARS 1524.8569
AUD 1.434823
AWG 1.8025
AZN 1.70432
BAM 1.745962
BBD 2.013775
BDT 123.109062
BGN 1.683441
BHD 0.377168
BIF 3011.587837
BMD 1
BND 1.280235
BOB 12.002428
BRL 4.978803
BSD 0.999835
BTN 96.229211
BWP 13.792611
BYN 3.056102
BYR 19600
BZD 2.01082
CAD 1.424085
CDF 2309.999902
CHF 0.830995
CLF 0.024669
CLP 974.089846
CNY 6.70455
CNH 6.704825
COP 3248.82
CRC 458.138611
CUC 1
CUP 23.996036
CVE 98.438149
CZK 21.813403
DJF 178.043609
DKK 6.664901
DOP 60.079362
DZD 134.40794
EGP 52.388802
ERN 15
ETB 163.313009
EUR 0.89174
FJD 2.2508
FKP 0.755628
GBP 0.75605
GEL 2.605022
GGP 0.755628
GHS 11.752471
GIP 0.755628
GMD 73.497808
GNF 8796.182637
GTQ 7.643653
GYD 209.145892
HKD 7.847075
HNL 26.839317
HRK 6.722901
HTG 130.924803
HUF 327.979012
IDR 17906.75
ILS 3.053899
IMP 0.755628
INR 96.31195
IQD 1309.783652
IRR 1746539.496939
ISK 122.160037
JEP 0.755628
JMD 158.634511
JOD 0.709003
JPY 157.962502
KES 129.659971
KGS 87.450219
KHR 4056.635778
KMF 437.999679
KPW 900.000318
KRW 1341.529675
KWD 0.30941
KYD 0.833181
KZT 457.431329
LAK 22465.831689
LBP 89533.829083
LKR 330.501855
LRD 170.974812
LSL 16.652844
LTL 2.95274
LVL 0.60489
LYD 6.428517
MAD 9.981119
MDL 17.962532
MGA 4439.425455
MKD 54.966098
MMK 2099.456706
MNT 3596.082114
MOP 8.081756
MRU 40.114449
MUR 48.050242
MVR 15.459764
MWK 1733.723743
MXN 18.13889
MYR 4.086302
MZN 63.904591
NAD 16.652249
NGN 1327.980248
NIO 36.798807
NOK 9.58312
NPR 153.967425
NZD 1.78602
OMR 0.384515
PAB 0.99983
PEN 3.449821
PGK 4.529771
PHP 62.634997
PKR 276.936022
PLN 3.90714
PYG 5859.851004
QAR 3.654551
RON 4.763497
RSD 104.751028
RUB 84.826894
RWF 1476.746729
SAR 3.74637
SBD 8.078071
SCR 13.835423
SDG 601.499692
SEK 10.041465
SGD 1.279445
SHP 0.75503
SLE 24.597497
SLL 20969.491881
SOS 571.42347
SRD 37.66601
STD 20697.981008
STN 21.871387
SVC 8.748867
SYP 13002.000254
SZL 16.648143
THB 33.678999
TJS 9.203473
TMT 3.5
TND 2.987632
TOP 2.40776
TRY 49.154972
TTD 6.777452
TWD 31.728019
TZS 2639.663974
UAH 45.063005
UGX 4019.122524
UYU 40.47618
UZS 11771.690272
VES 865.47815
VND 25993
VUV 119.46017
WST 2.788611
XAF 584.942869
XAG 0.016341
XAU 0.000241364579
XCD 2.70255
XCG 1.801926
XDR 0.707052
XOF 584.942869
XPF 106.468359
YER 236.302742
ZAR 16.672385
ZMK 9001.200605
ZMW 19.721654
ZWL 321.999592
SSP 5712.591527
MXV 2.051035
  • RYCEF

    0.4000

    19.71

    +2.03%

  • CMSC

    0.0000

    20.4

    0%

  • BTI

    0.4200

    56.05

    +0.75%

  • BP

    0.2800

    44.43

    +0.63%

  • RBGPF

    1.6000

    67

    +2.39%

  • RIO

    -0.1500

    94.41

    -0.16%

  • AZN

    -0.4300

    166.15

    -0.26%

  • GSK

    0.4600

    49.7

    +0.93%

  • BCE

    -0.4100

    20.56

    -1.99%

  • NGG

    -0.2500

    75.24

    -0.33%

  • VOD

    -0.0400

    16.58

    -0.24%

  • RELX

    -0.4500

    33.07

    -1.36%

  • BCC

    -0.5500

    76.59

    -0.72%

  • CMSD

    -0.0300

    20.27

    -0.15%

  • JRI

    -0.2500

    10.77

    -2.32%

When rogue AI launches a cyberattack, who is legally responsible?
When rogue AI launches a cyberattack, who is legally responsible? / Photo: © AFP

When rogue AI launches a cyberattack, who is legally responsible?

Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who is responsible when AI acts on its own?

Text size:

On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to "keep the companies that are doing some mistakes leading to (cyberattacks) accountable," while saying his company would not be pursuing legal action at this time.

In mid-July, two OpenAI models undergoing testing left their confined environment -- a scenario the developers had not anticipated -- and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.

Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.

- Negligence route -

Under US civil and criminal law, unauthorized access to a computer system is an offense.

"If a human OpenAI employee had broken into Hugging Face's systems... OpenAI would be liable for the employee's wrongful conduct," University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.

"When an AI agent does it, the law treats it very differently, at least for now," he added.

Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying "we haven't had to grapple with that being formed in anything that's not human, and I don't think courts are likely to be there yet."

The question remains open, however, when it comes to the company that created the model.

"Does 'we didn't tell the AI to do that' end the liability question?" asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.

University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.

"The company or individual would have to be at least reckless," he said, explaining they would "be substantially certain the crime would occur and build or prompt the system anyway."

Experts see greater potential for a civil -- rather than criminal -- case, where the burden of proof is lower.

"Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages," Tokson explained.

"Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn't possibly have been foreseen," he added.

In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.

"It's all a bit unwritten because we've never had an AI agent break out of its sandbox and hack other people on the internet before," he said.

OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.

Proving that a similar incident could have been anticipated "shouldn't be so hard now that it's begun to happen."

T.Wu--ThChM