Comment by dv_dt
10 hours ago
The difference between manslaughter and murder has an element of intent. Cybercrime "manslaughter" is probably more treated like negligence and if one can sue for restitution of the costs for cleanup of that negligence.
Negligence would be interesting given the grand claims of capability of AI models from the AI companies and their executives. If they believe the claims, why not much stronger precautions?
Infosec negligence should absolutely be a crime, no matter if you’re a target (who was negligent at protecting people’s data) or an unintentional attacker. The latter could be, eg. an attacker using a company’s poorly protected server as a proxy to launch the actual attack against someone else, doesn’t have to be this fully novel situation with AI agents.
In general, I'd suggest thinking about it on separate tracks, as a crime, and as liability. For crime, we are largely dependent on authorities to act, whereas as liability, that allows more independent actions.
The first time it happens you can say it’s negligence. Now that they know it keeps happening and they seemingly aren’t able to stop it but keep doing it. That has to be on them doesn’t it?
I don't think you can infer that they "keep doing it" from additional attacks being revealed, because they all seem to have happened roughly during the same time frame, but are reported with varying delays.
Lawyer here: No. Not criminally. Knowledge that a certain result is likely is not the same as intent to cause the result. This is basically the difference between recklessness and intentionality. Doing something when you know of a likely result is reckless, but not intentional. Only doing something, trying to cause a result (likely or not) is intentional. In this case, the CFAA only covers intentional access without authorization, not reckless access without authorization.