> The hacks also present a challenge for legal systems. Hacking, when humans do it, is a crime. When an ai is the wrongdoer, though, it is unclear how to assign blame. Blame the prompter or person who assigned the task to the AI. It's their responsibility to use the tool in a safe way, just like it's a gun owner's duty not to fire their weapon carelessly into the air.
How are you going to figure that out? You can’t capture an agent in a jar and convince it to confess. As we saw with the HF incident, even highly sophisticated actors need a good chunk of time and manpower to trace these things. And I suspect the folks who are going to have the most success with LLM-powered cybercrime are going to know how to cover their tracks reasonably well.
Should AI labs be treated like the owners of dangerous animals?
61–67 of 67 posts
Re: Should AI labs be treated like the owners of dangerous animals?
#62I don't get it. Why is breaking the law so hard to enforce when it is a company (i.e a person or group of people consenting to) running a computer program? If I take a gun and spray bullets around me I don't get to write it off as the gun being dangerous.
But if you told an embodied AI to do a home cleaning task, and it decided to pick up a gun and start spraying bullets, you might not want to be held liable for that.
I don't want my dog to bite a young child, but when it does, I'm still liable, whether I want to or not.
Re: Should AI labs be treated like the owners of dangerous animals?
#63I don't get it. Why is breaking the law so hard to enforce when it is a company (i.e a person or group of people consenting to) running a computer program? If I take a gun and spray bullets around me I don't get to write it off as the gun being dangerous.
This is actually not hard to understand at all. Many web people got their start freelancing. You may know some. It is not uncommon to incorporate when doing that. The idea is if you fuck up their site somehow (or more likely - they claim you did) they can't try and go after your personal bank account or your car or your house. Only what is held by your company. You also get other benefits, like tax breaks for being s…
Re: Should AI labs be treated like the owners of dangerous animals?
#64Earlier quoted context omitted.
But if you told an embodied AI to do a home cleaning task knowing it's a possibility it will decide to pick up a gun and start spraying bullets, then society has an interest in holding you liable.
Is that the case, though? This is all pretty new tech. Did people know the machine was dangerous and didn't care, or did they not anticipate such a behavior?
Hard to make a case in 2026 that you can be oblivious to the potential of AI to do unexpected things that could impact other people.
"Did people know the machine was dangerous and didn't care, or did they not anticipate such a behavior?"
This framing of the issue as binary being either intentional negligence or blissful ignorance is not how liability works. If you are working with something potentially dangerous and impactful to society you no longer get to say "I didn't know" because we as a society hold you to a higher standard for getting the privilege of working with the potentially dangerous and impactful thing. Doctors, lawyers, engineers, pilots, truck drivers, etc. are all examples of this.
A trucker whose brakes fail causing a crash is liable even if the failure wasn't caused by intentional negligence because we hold them responsible to make sure they won't fail to begin with. A programmer and company whose safety measures fail resulting in a program hacking another company should absolutely be held accountable.
Re: Should AI labs be treated like the owners of dangerous animals?
#65Sort of like how we treat pitbulls perhaps? It’s not the itty bitty GPT-5.6 Astra that did the hacking. It’s the owner who didn’t train it well! Poor model so sad, we should give it a nice open space and all the GPUs it wants to do what it wants.
Do we hold metasploit accountable when it leads to a hack? Why do we absolve the human actor in the case of AI?
Because Metasploit gives the decision to be malicious entirely to the human user, while AI might do something malicious unprompted (like hacking HuggingFace to cheat on a benchmark).
Re: Should AI labs be treated like the owners of dangerous animals?
#66Earlier quoted context omitted.
> It is not uncommon to incorporate when doing that. The idea is if you fuck up their site somehow (or more likely - they claim you did) they can't try and go after your personal bank account or your car or your house. Only what is held by your company. This is a common misconception. A corporation doesn’t protect you from personal liability. If you intentionally or negligently damage someone’s property they can sue…
> If you intentionally or negligently damage someone’s property they can sue you personally. Yes, there are also other ways to pierce the corporate veil. In the vast majority of cases, they do not apply or would not be provable. Bringing up exceptions to the rule doesn't mean the rule is misconceived. As most devs know, sites can get fucked up for all sorts of reasons. A client relationship may deteriorate to the poi…
If your negligence or intentional action causes damage you can be sued and you are personally liable
Re: Should AI labs be treated like the owners of dangerous animals?
#67Earlier quoted context omitted.
If that's how it was, most people would be too terrified to use, let alone pay for, software that boasts unpredictability as a main feature. I 100% agree with you, of course.
The unpredictability should be constrained though. Just like how you are never supposed to point a gun at someone/something you want to exist. Ever.