Comment by VyseofArcadia

8 hours ago

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

  • There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.

  • Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI?

    Sorry if it is a stupid question, as mentioned above I am legally naïve.

    • Companies can certainly be charged with crimes. Punishments can be via fines or sanctions (court appointed monitors, etc).

      Individual employees can also be charged for their specific actions as part of the performance of a crime.

    • I, too, have no idea about legal matters.

      But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust.

      I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc.

      2 replies →

    • As far as I know (IANAL) it is in fact the only "person" you can charge. To the best of my knowledge, the whole point these "limited liability" legal constructions exist in the first place, is to protect individuals within a corporation for whatever they do as part of the business of a company (barring exceptions that have clearly not been part of that business and obvious individually committed crimes), typically "just following orders". If a company commits a crime, or in a worse case runs a criminal enterprise, it is the company that is legally responsible, not its employees. That is, in principle.

      This can get more complicated higher up the management tree, where decisions can also be prosecuted on personal little, but that's usually a far more complicated matter. Also, if a whole group of employees willingly conspires to commit crimes, they might also be prosecuted individually for those crimes (there are limits to limited liabilities). However, that usually only works under special conditions and it would e.g. require that there's an obvious criminal enterprise aspect to it, rather than individual cases of illegal conduct.

      That said, with the track record of some of these companies, actually designating some of the AI companies as a criminal enterprises may eventually happen (in due time) in some jurisdictions outside the USA. Certainly if it ever turns out that these companies have been storing and (ab)using everything they ever had access too, while blatantly lying about that just because some particular (post 9/11) US laws gives them that opportunity (and impunity) as long as the US government somehow requested them to do so (covertly; with gag order). Might legally work withing US jurisdiction, but would still be very much illegal everywhere else.

      1 reply →

  • It doesn't need to be twisted to violate the DMCA anticircumvention clause because it is already just plain old hacking.

  • > the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

    Was not that the goal when companies started using AI for their customer support? Be able to say anything without legal repercussions...

    But then this happened: https://www.bbc.com/travel/article/20240222-air-canada-chatb...

    And support chatbot got a reality cold shower.

    The law will find a way to charge people in particular. Sadly will start with the less powerful in the chain before it actually acts on the people that can actually change things.

  • How is the responsibility diluted? Charge the CEO…

    • Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction.

      Do you think there is evidence of this?

      10 replies →

  • A copyright law seems an odd place to start. This is computer misuse.

    • The DMCA is a bit overly broad to be considered just a copyright law. For example, just breaking encryption on a DVD is technically illegal regardless of whether you then go on to do something otherwise illegal (make and sell bootlegs) or perfectly legal (make a space-shifted backup copy on your hard drive).

      IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. They had to find a way to make doing the same with DVDs illegal.

      5 replies →

  • Issuing subpeonas, raiding offices, and dragging key employees into interrogation rooms as you would find in any normal criminal investigation would be more than enough to ensure "AI safety" without any new regulations, acts of congress, Bernie Sanders campaign speeches, or even charges filed.

Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry...

Maybe, but do you need to prove intent? Of the people, not the AI.

Accidents often have penalties associated with them too, but usually there's a difference between accidents and purposeful actions.

  • Accidents could result in bioweapons falling into the wrong hands and killing more Americans than COVID has so far, and allowing for those types of accidents without effective regulation is a purposeful action.

Criminal law may be lagging or inapplicable. (Crimes require "mens rea", a "guilty mind")

Tort law is very general: Contribute toward harming someone -> civil suit for damages $$$

Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title.

I'm going to assume that this will never happen

They are too busy pulling Andre to court, so they have no resources going against OpenAI. Shopify wants to make profit, not waste time in a court case against TechBro bromance brother corporations.