| ▲ | tptacek an hour ago | |
Obviously, the labs (or any other operator of a model) should be accountable for malicious or destructive actions taken by agents. And they are. I don't think there's any controversy about the civil liability exposure frontier labs have if their agents cause damages, and it is remarkably easy to rack up damages by causing computer intrusions even if those intrusions don't cause obvious direct damages; for instance, many organizations are required to engage forensics firms at nosebleed-high costs to assess the impact of breakins in order to retain insurance coverage. The "controversy", if you want to call it that, is over criminal liability. People feel that frontier labs should be at least as responsible criminally as human hackers are when they're caught (to be clear: an extraordinarily rare outcome). The problem is: they're not criminally liable, not so long as the frontier labs operate without specific intent to cause breakins. Mens rea thresholds are their own whole area of criminal law, and there are stark differences between "recklessness" and "intent". All of the meaningful criminal CFAA predicates require actual intent: someone, a human being, has to deliberately set out to create the outcome where a specific intrusion happens. They have to want it to happen and act accordingly. In the most severe cases, they also have to do so with intent to defraud. We could change the law to make it easier to prosecute breakins without provable intent, but I don't think that would make HN people happier. | ||