Comment by user43928

9 hours ago

In the US, hacking laws require intent.

Software behaving differently than intended is therefore not a crime under these laws.

Negligence is still a possibility, if there are significant reasonably foreseeable consequences.

  • I think there’s a strong argument that it was hard to foresee the consequences since it was all new. This won’t be true if those incidents continue happening tho.

  • Where does negligence come into play?

    In criminal hacking law that explicitly requires intent, or a civil lawsuit about damages?

    I honestly don't know, but my guess would be the latter.

I think a competent DA could easily prove that, if you know the model is capable of performing unauthorized breaches into third-party systems when given a task, and you give it a task that could require it to do so, intent is present.

  • It's not a complicated distinction:

    If you think they intentionally had their model hack third-party systems, you could do a criminal investigation.

    I do not think that this is reasonable to believe given that clearly the VMs were not intended to have internet access and that committing such crimes wasn't in anyone's interest.

  • Do you have an example where they gave a task that required breaching in a way that was easily foreseeable ?