| ▲ | glub 9 hours ago | ||||||||||||||||
Even if you take out the LLMs out of the equation, it's at the very least a negligence. Model didn't escape a sandbox, as there was no sandbox. | |||||||||||||||||
| ▲ | IanCal 8 hours ago | parent | next [-] | ||||||||||||||||
Perhaps I’m not being as strict with the word sandbox but they were sandboxed right? They did not have generic internet access they exploited other software to make external requests. | |||||||||||||||||
| |||||||||||||||||
| ▲ | skissane 8 hours ago | parent | prev [-] | ||||||||||||||||
Yes, but negligence is more commonly a tort than a crime. Negligence is generally only criminalised in certain narrow cases, e.g. when it causes human deaths or serious physical injuries And tort law only works when the plaintiff believes it is in their overall interest to sue. If a corporation decides it isn't in their strategic interest to sue a partner corporation, nobody can make them. And even if they do sue, the amount necessary to settle a small cybersecurity incident is likely well within the budget of a megavendor. | |||||||||||||||||