Comment by Sharlin

9 hours ago

Infosec negligence should absolutely be a crime, no matter if you’re a target (who was negligent at protecting people’s data) or an unintentional attacker. The latter could be, eg. an attacker using a company’s poorly protected server as a proxy to launch the actual attack against someone else, doesn’t have to be this fully novel situation with AI agents.

In general, I'd suggest thinking about it on separate tracks, as a crime, and as liability. For crime, we are largely dependent on authorities to act, whereas as liability, that allows more independent actions.