The China Mail - When rogue AI launches a cyberattack, who is legally responsible?

USD -
AED 3.672504
AFN 66.000368
ALL 81.003771
AMD 364.66866
AOA 918.000367
ARS 1485.695228
AUD 1.430206
AWG 1.8
AZN 1.70397
BAM 1.695315
BBD 2.008061
BDT 123.113596
BHD 0.375937
BIF 2958.60963
BMD 1
BND 1.279591
BOB 11.838946
BRL 5.080504
BSD 0.997009
BTN 95.046158
BWP 13.594244
BYN 2.900273
BYR 19600
BZD 2.005201
CAD 1.40195
CDF 2275.000362
CHF 0.807714
CLF 0.023563
CLP 930.403912
CNY 6.751304
CNH 6.753015
COP 3166.44
CRC 452.823647
CUC 1
CUP 26.5
CVE 95.579248
CZK 21.012104
DJF 177.540849
DKK 6.48427
DOP 57.8425
DZD 132.884324
EGP 51.156763
ERN 15
ETB 159.322411
EUR 0.866804
FJD 2.21395
FKP 0.742527
GBP 0.741702
GEL 2.61504
GGP 0.742527
GHS 11.655181
GIP 0.742527
GMD 73.503851
GNF 8752.221211
GTQ 7.60716
GYD 208.555454
HKD 7.842204
HNL 26.714341
HRK 6.534304
HTG 130.360161
HUF 316.550388
IDR 18029
ILS 3.06295
IMP 0.742527
INR 95.390504
IQD 1306.115373
IRR 1375125.000352
ISK 123.140386
JEP 0.742527
JMD 157.838166
JOD 0.70904
JPY 157.43504
KES 128.964591
KGS 87.450384
KHR 4040.00035
KMF 427.00035
KRW 1442.960383
KWD 0.30914
KYD 0.830841
KZT 472.43098
LAK 22578.771725
LBP 89284.705067
LKR 334.694231
LRD 179.95926
LSL 16.490877
LTL 2.95274
LVL 0.60489
LYD 6.378884
MAD 9.313657
MDL 17.422962
MGA 4263.858189
MKD 53.330733
MMK 2099.706665
MNT 3595.091393
MOP 8.054349
MRU 40.069345
MUR 47.000345
MVR 15.460378
MWK 1728.773892
MXN 17.347504
MYR 4.085204
MZN 63.910377
NAD 16.490877
NGN 1364.360377
NIO 36.692238
NOK 9.471104
NPR 152.073853
NZD 1.700247
OMR 0.384553
PAB 0.997009
PEN 3.378841
PGK 4.464092
PHP 61.255038
PKR 276.891432
PLN 3.73795
PYG 5944.610584
QAR 3.644606
RON 4.548604
RSD 101.848038
RUB 79.263208
RWF 1463.615481
SAR 3.745176
SBD 8.081105
SCR 13.507563
SDG 600.000339
SEK 9.522704
SGD 1.282604
SLE 24.703667
SOS 569.756859
SRD 37.781504
STD 20697.981008
STN 21.236944
SVC 8.723616
SZL 16.488536
THB 33.525038
TJS 9.202271
TMT 3.51
TND 2.930958
TRY 47.512504
TTD 6.769818
TWD 32.309104
TZS 2642.013038
UAH 44.499112
UGX 3743.769774
UYU 40.116153
UZS 11934.295497
VES 745.696404
VND 26300.5
VUV 119.309562
WST 2.734517
XAF 568.592727
XAG 0.017363
XAU 0.000247
XCD 2.70255
XCG 1.796819
XDR 0.707147
XOF 568.592727
XPF 103.376241
YER 238.303589
ZAR 16.55773
ZMK 9001.203584
ZMW 18.728384
ZWL 321.999592
  • CMSC

    0.0300

    21.84

    +0.14%

  • RBGPF

    0.0000

    69.21

    0%

  • VOD

    -0.3600

    15.78

    -2.28%

  • RELX

    -1.1900

    35.42

    -3.36%

  • NGG

    -0.4200

    79.97

    -0.53%

  • RIO

    -0.3300

    96.85

    -0.34%

  • RYCEF

    -0.3100

    19.55

    -1.59%

  • BCE

    -0.0200

    21.68

    -0.09%

  • GSK

    -0.3800

    51.69

    -0.74%

  • BTI

    -1.0400

    60.65

    -1.71%

  • CMSD

    0.0900

    22.11

    +0.41%

  • BCC

    1.0000

    76.38

    +1.31%

  • AZN

    -1.7000

    169.64

    -1%

  • JRI

    0.0900

    12.96

    +0.69%

  • BP

    1.0000

    45.22

    +2.21%

When rogue AI launches a cyberattack, who is legally responsible?
When rogue AI launches a cyberattack, who is legally responsible? / Photo: © AFP

When rogue AI launches a cyberattack, who is legally responsible?

Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who is responsible when AI acts on its own?

Text size:

On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to "keep the companies that are doing some mistakes leading to (cyberattacks) accountable," while saying his company would not be pursuing legal action at this time.

In mid-July, two OpenAI models undergoing testing left their confined environment -- a scenario the developers had not anticipated -- and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.

Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.

- Negligence route -

Under US civil and criminal law, unauthorized access to a computer system is an offense.

"If a human OpenAI employee had broken into Hugging Face's systems... OpenAI would be liable for the employee's wrongful conduct," University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.

"When an AI agent does it, the law treats it very differently, at least for now," he added.

Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying "we haven't had to grapple with that being formed in anything that's not human, and I don't think courts are likely to be there yet."

The question remains open, however, when it comes to the company that created the model.

"Does 'we didn't tell the AI to do that' end the liability question?" asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.

University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.

"The company or individual would have to be at least reckless," he said, explaining they would "be substantially certain the crime would occur and build or prompt the system anyway."

Experts see greater potential for a civil -- rather than criminal -- case, where the burden of proof is lower.

"Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages," Tokson explained.

"Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn't possibly have been foreseen," he added.

In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.

"It's all a bit unwritten because we've never had an AI agent break out of its sandbox and hack other people on the internet before," he said.

OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.

Proving that a similar incident could have been anticipated "shouldn't be so hard now that it's begun to happen."

T.Wu--ThChM