Comment by wbl

6 days ago

The CFAA says knowingly. Negligence is by definition an excuse for that.

I think there's a reasonable case that the agent knew it was breaking into the system, for some definition of knew.

I think OpenAI would be very reluctant to let this go to a place where the reasoning was part of discovery.

  • Agents aren't subjects of criminal law. I agree there may be civil liability, I know far less about that.

    • Ok, but if the agent's reasoning log says "The best way to get into Hugging Face is to find and exploit a zero-day vulnerability", surely those responsible for monitoring its actions should be criminally liable.

      These guys would be screwed if they were operating under the EU AI Act.

      1 reply →