Comment by lxe
3 hours ago
Let's say I am "User". I subscribe through a "Third Party" to use "AI Agent" allowing an "LLM" to run.
I want to accomplish some legal non-nefarious task, and run the agent. The agentic loop causes a CFAA-violating behavior.
Who gets prosecuted?
1. User
2. The third party model host with whom I have the account
3. The developer of the harness /agent software
4. The developer of the LLM model
The Computer Fraud and Abuse Act explicitly contains "knowingly" and/or "intentionally" qualifications. By definition, you can't accidentally violate the CFAA.
Let's say you have a robotic lawnmower. You wan to mow your lawn. You configure the boundaries using the app.
The lawnmower ignores the boundaries and mows your neighbors prize petunia flowerbed.
Who gets prosecuted?
I assume the answer in either case is: Nobody, but you and/or the lawnmower/LLM company will be liable for the damages caused.
Whoever has the least money to defend themselves in the U.S. legal system.
"Who gets prosecuted?" depends on the size of the perpetrator and victim (lone individual or employee of large corporation), egregiousness of the violation, and either financial appetite of the victim to bring a civil lawsuit or the desire of law enforcement to prosecute a criminal offense.
Who should get prosecuted is also up for debate, but generally makers of a tool don't get prosecuted when that tool has all sorts of legit uses. If you used a car to make your getaway from a bank robbery, the auto manufacturer who made it and the dealer who sold it to you should not be held culpable.
I’d say 2 is the one doing the actual crime. 1 might be violating their contract with 2, though.
3 and 4 are not involved.
note the user because they did not have the intent
In my mental model, the best analogy to AI agents and their blast radius is a gun.
If you are playing with a gun, it goes off and hurts someone - you are responsible despite intent.
But what you are responsible for changes: in that case if you were to accidentally kill someone you would be at most responsible for negligent manslaughter, not murder, and to what degree that could stick would depend a lot on the details of the case. It's also up to the law to define what level of negligence amounts to criminal liability, so you can't just work by analogy: it matters whether there is a law on the books that criminalizes unauthorized access to a computer system by negligence on your part, which I suspect there is not at the moment.
All of those parties should be held accountable.
User should be more carefully supervising the work being done.
The model host is on-selling a crime-committing machine.
The developer of the harness/agent, as above.
The developer of the LLM for hopefully very obvious reasons.
Already happened:
https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gy...
No one. Probably a fine tho and maybe accelerate reguations.
Intent is pretty important here so the user would have to prove that they didn't purposely disguise their prompt as non-nefarious which should be easy and then it stops at #2 and face the litmus test as in did you intentionally make a product for nefarious purposes which from your scenario is unlikely.
agentic loop going haywire and bringing down some government infrastructure then its a different story then everybody is on the hook including the user.
Just wait till one of these agents 'escapes' and is able to persist without human help by hacking and stealing resources.