Good luck getting any form of punishment even if found guilty. It's a department of war contractor... People who disrupt things like that end up committing suicide.
It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.
I don't think this true. If I throw a brick out my window and it hurts someone, I can still be held criminially liable, even if I didn't mean to do it.
Do drunk drivers intionally kill people on the road?
Not a lawyer, but the other responder definitely isn’t either.
Whether intent is required is down to how the law is written. For many offenses “strict liability” applies, where intent is not required, they only have to prove you did it, not what your intent was.
DUI is typically a strict liability crime. They don’t need to prove that you intended to drive drunk, only that you did drive drunk.
Intent is the difference between murder and manslaughter, in that case. Drunk driving is common enough that prosecutors will argue that getting drunk in a situation where you have to drive is intent. Get OpenAI convicted of unintentional CFAA first, then say that the negligence qualifies as intent, I suppose.
There are different levels of intent. Take murder, for example. A premeditated murder - you sat down, in a completely calm state, and made an affirmative decision to kill a specific person, and then you went out and did it - is the highest class of murder you can commit. If you go out generally looking to be violent in a way that kills people, and you kill someone, that's still murder, but it's a step down.
But even if you didn't deliberately intend for something bad to happen, you may have been reckless. For example, you might decide to drive 90 miles per hour in a 25 mph zone. You could have a completely pure heart, but you are acting without regard for the safety of others, so you're reckless. That is enough for certain crimes and for civil liability in nearly all cases.
Then there's negligence, where you're not taking reasonable care to avoid harm to others. Negligence usually isn't enough to support criminal liability - especially for felonies - but it is enough to win a civil lawsuit over most things.
And then, as another commenter noted, there is strict liability, where there are certain things you are just not allowed to do no matter how careful you are about them or how pure your intentions are.
For what it's worth, this is not totally uncharted territory for the law. AI agents are brand new, yes, but agency relationships have been recognized by the law for centuries. Generally speaking, if someone acts negligently while they are carrying out a task at your direction, you can be held responsible. Obviously this is fact-dependent, but I don't see any reason why it would be different if the agent is made of silicon rather than carbon. It holds true, with various nuances, even for less-than-human instrumentalities like a pet or an otherwise-lawful weapon.
Whether it’s intentional requires a legal investigation to establish. Since when is “hey we didn’t mean it!” in a corporate press release enough to establish lack of intent in a criminal matter?
>It’s interesting that a lot of U.S. law requires intent.
mens rea and the shift from responsibility to moral guilt is genuinely one of the stupidest legal innovations anyone has ever come up with, it's like affirmative action for imbeciles, in particular in a world of autonomous machines.
"sorry my self driving car ran you over on the way home, didn't think it could happen, sorry it did though"
I think this is a genuine reason to be bullish on the legal traditions like Nordic tort law or East Asian collective responsibility when it comes to adoption of these technologies.
Weren't we talking about criminal liability, though? And ‘tort’ — in addition to sounding like something you'd rather eat during a kaffepaus with those Nordic buddies of yours — is so common-law(ish) that if asking for trouble were a crime, using it in dialogue with those Nordic lawyers could well be deemed as intentional under most current local varities of criminal law theory up there, perhaps merely because you surely must've considered that consequence "quite probable", at minimum, or due to your indifference toward the same (or some combination of these) ;)
> We have a word for attack with no intent. It's accident.
And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.
Because right now the Department of Justice is shut down for causes that the administration supports, which includes OpenAI, and none of the victims want to sue over it.
And the republicans in the states are being shitty too. They tried to block their own state attorneys general from protecting the state and opposing Trump in NC.
No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.
Tell that to the script kiddies with a criminal record for "hacking" into their school's computer systems by entering "username: admin" and "password: password".
Right, because in that case you'd have a hard time convincing the court that the access wasn't intentional. You might not know the law existed, but you intended to access the system. You'd have a pretty solid defense if you ran a crawler that was crawling every website ever, and stumbled upon some secure site. In fact there are companies which does this exact thing, eg. shodan.
Exactly. Think what would happen if it was a Chinese LLM company behind such an attack...
Who could possibly hold them accountable?
OpenAI is currently under investigation by a coalition of state attorney generals: https://www.nytimes.com/2026/06/13/technology/states-investi...
A state coalition extracted $17B from Meta earlier this year, so consequences can happen, although our legal system moves very slowly.
A district attorney that would want to make themselves a name, perhaps?
Good luck getting any form of punishment even if found guilty. It's a department of war contractor... People who disrupt things like that end up committing suicide.
1 reply →
It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.
I don't think this true. If I throw a brick out my window and it hurts someone, I can still be held criminially liable, even if I didn't mean to do it.
Do drunk drivers intionally kill people on the road?
Not a lawyer, but the other responder definitely isn’t either.
Whether intent is required is down to how the law is written. For many offenses “strict liability” applies, where intent is not required, they only have to prove you did it, not what your intent was.
DUI is typically a strict liability crime. They don’t need to prove that you intended to drive drunk, only that you did drive drunk.
14 replies →
Intent is the difference between murder and manslaughter, in that case. Drunk driving is common enough that prosecutors will argue that getting drunk in a situation where you have to drive is intent. Get OpenAI convicted of unintentional CFAA first, then say that the negligence qualifies as intent, I suppose.
CFAA says doesn't require intent, you use a computer system the way it "wasn't intended", you're liable.
They can still be held civilly liable for negligence, though.
the charges here would depend on negligence and acting recklessly.
we might get something if they tried to cover it up.
There are different levels of intent. Take murder, for example. A premeditated murder - you sat down, in a completely calm state, and made an affirmative decision to kill a specific person, and then you went out and did it - is the highest class of murder you can commit. If you go out generally looking to be violent in a way that kills people, and you kill someone, that's still murder, but it's a step down.
But even if you didn't deliberately intend for something bad to happen, you may have been reckless. For example, you might decide to drive 90 miles per hour in a 25 mph zone. You could have a completely pure heart, but you are acting without regard for the safety of others, so you're reckless. That is enough for certain crimes and for civil liability in nearly all cases.
Then there's negligence, where you're not taking reasonable care to avoid harm to others. Negligence usually isn't enough to support criminal liability - especially for felonies - but it is enough to win a civil lawsuit over most things.
And then, as another commenter noted, there is strict liability, where there are certain things you are just not allowed to do no matter how careful you are about them or how pure your intentions are.
For what it's worth, this is not totally uncharted territory for the law. AI agents are brand new, yes, but agency relationships have been recognized by the law for centuries. Generally speaking, if someone acts negligently while they are carrying out a task at your direction, you can be held responsible. Obviously this is fact-dependent, but I don't see any reason why it would be different if the agent is made of silicon rather than carbon. It holds true, with various nuances, even for less-than-human instrumentalities like a pet or an otherwise-lawful weapon.
Whether it’s intentional requires a legal investigation to establish. Since when is “hey we didn’t mean it!” in a corporate press release enough to establish lack of intent in a criminal matter?
At some point that recklessness looks like intent
>It’s interesting that a lot of U.S. law requires intent.
mens rea and the shift from responsibility to moral guilt is genuinely one of the stupidest legal innovations anyone has ever come up with, it's like affirmative action for imbeciles, in particular in a world of autonomous machines.
"sorry my self driving car ran you over on the way home, didn't think it could happen, sorry it did though"
I think this is a genuine reason to be bullish on the legal traditions like Nordic tort law or East Asian collective responsibility when it comes to adoption of these technologies.
Weren't we talking about criminal liability, though? And ‘tort’ — in addition to sounding like something you'd rather eat during a kaffepaus with those Nordic buddies of yours — is so common-law(ish) that if asking for trouble were a crime, using it in dialogue with those Nordic lawyers could well be deemed as intentional under most current local varities of criminal law theory up there, perhaps merely because you surely must've considered that consequence "quite probable", at minimum, or due to your indifference toward the same (or some combination of these) ;)
We have a word for attack with no intent. It's accident.
> We have a word for attack with no intent. It's accident.
And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.
i think (criminal) negligence is more like it
Because right now the Department of Justice is shut down for causes that the administration supports, which includes OpenAI, and none of the victims want to sue over it.
State government exists, contrary to popular belief.
And the republicans in the states are being shitty too. They tried to block their own state attorneys general from protecting the state and opposing Trump in NC.
No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.
Tell that to the script kiddies with a criminal record for "hacking" into their school's computer systems by entering "username: admin" and "password: password".
Right, because in that case you'd have a hard time convincing the court that the access wasn't intentional. You might not know the law existed, but you intended to access the system. You'd have a pretty solid defense if you ran a crawler that was crawling every website ever, and stumbled upon some secure site. In fact there are companies which does this exact thing, eg. shodan.
If any remediation was required, that's damage. This looks a lot smaller than the HuggingFace hack but it still required some cleanup.
Remediation mostly involved repairing pre-exising holes in the fences that the dog crawled through.
2 replies →
That's not really true. Unauthorized access to a system is a crime regardless if there was damage.
https://www.law.cornell.edu/uscode/text/18/1030
You read your own source?
>having knowingly accessed [...]
>intentionally accesses a computer without authorization [...]
1 reply →
Ah I see you're releasing OpenAI from being the one controlling the tools and giving the agent agency.
I'd argue they intentionally accessed systems they weren't meant to as they were the ones running the bots.
I don't think you or I would get the same leniency if a bot on our network did the same.
2 replies →
> No harm, no foul.
What? That’s not how criminal law works, at all.
Yes, that's actually how it works: https://en.wikipedia.org/wiki/Mens_rea
4 replies →