Zürcher Nachrichten - When rogue AI launches a cyberattack, who is legally responsible?

EUR -
AED 4.138305
AFN 73.24455
ALL 91.999344
AMD 407.439965
ANG 2.017449
AOA 1034.43644
ARS 1713.059431
AUD 1.613917
AWG 2.028306
AZN 1.912859
BAM 1.957879
BBD 2.266938
BDT 138.32612
BGN 1.896963
BHD 0.424375
BIF 3382.817977
BMD 1.126837
BND 1.439092
BOB 13.533193
BRL 5.608381
BSD 1.12556
BTN 108.463603
BWP 15.482719
BYN 3.457726
BYR 22086.001101
BZD 2.263474
CAD 1.606137
CDF 2614.261575
CHF 0.935832
CLF 0.027676
CLP 1092.802716
CNY 7.554933
CNH 7.549917
COP 3612.244359
CRC 515.267833
CUC 1.126837
CUP 27.011689
CVE 110.376351
CZK 24.403001
DJF 200.423755
DKK 7.474539
DOP 67.865089
DZD 151.737602
EGP 58.980215
ERN 16.902552
ETB 182.011395
FJD 2.531158
FKP 0.852579
GBP 0.848807
GEL 2.924116
GGP 0.852579
GHS 13.246893
GIP 0.852579
GMD 83.385694
GNF 9902.087998
GTQ 8.596703
GYD 235.471134
HKD 8.843162
HNL 30.2131
HRK 7.533695
HTG 147.383072
HUF 365.028076
IDR 20106.824962
ILS 3.434993
IMP 0.852579
INR 108.55433
IQD 1474.431388
IRR 1949596.67347
ISK 137.01221
JEP 0.852579
JMD 178.849953
JOD 0.798972
JPY 178.117401
KES 146.400496
KGS 98.541587
KHR 4558.821605
KMF 494.681497
KPW 1014.15347
KRW 1508.112893
KWD 0.348688
KYD 0.937913
KZT 507.968805
LAK 25238.581417
LBP 100784.499604
LKR 372.085184
LRD 192.457822
LSL 18.640998
LTL 3.327256
LVL 0.681612
LYD 7.234684
MAD 11.22372
MDL 20.084688
MGA 4985.250494
MKD 61.645472
MMK 2365.307218
MNT 4054.001791
MOP 9.098065
MRU 45.063861
MUR 53.423109
MVR 17.415237
MWK 1951.616071
MXN 20.238355
MYR 4.603579
MZN 72.016213
NAD 18.64224
NGN 1492.766071
NIO 41.416745
NOK 10.776267
NPR 173.54602
NZD 2.006096
OMR 0.433271
PAB 1.125485
PEN 3.875874
PGK 5.024559
PHP 70.676891
PKR 311.727179
PLN 4.364622
PYG 6594.003359
QAR 4.102557
RON 5.350898
RSD 117.443472
RUB 96.447793
RWF 1662.395102
SAR 4.222674
SBD 9.08066
SCR 15.653164
SDG 677.793137
SEK 11.243944
SGD 1.439198
SHP 0.852373
SLE 27.776491
SLL 23629.194937
SOS 643.211683
SRD 42.443398
STD 23323.246497
STN 24.526049
SVC 9.848027
SYP 14651.132242
SZL 18.635032
THB 37.838986
TJS 10.376683
TMT 3.955197
TND 3.357366
TOP 2.713152
TRY 55.416245
TTD 7.62917
TWD 35.780224
TZS 2971.653429
UAH 50.556839
UGX 4541.125287
USD 1.126837
UYU 45.415817
UZS 13258.081144
VES 980.662964
VND 29288.741869
VUV 135.531066
WST 3.136098
XAF 655.957
XAG 0.018311
XAU 0.000269843181
XCD 3.045333
XCG 2.028444
XDR 0.796732
XOF 655.957
XPF 119.331742
YER 266.215457
ZAR 18.591111
ZMK 10142.885124
ZMW 22.256342
ZWL 362.840987
SSP 6446.509185
MXV 2.287928
  • BTI

    0.3200

    53.2

    +0.6%

  • CMSC

    0.0440

    20.314

    +0.22%

  • RBGPF

    -2.1900

    62.9

    -3.48%

  • NGG

    0.5400

    76.56

    +0.71%

  • GSK

    0.1500

    46.7

    +0.32%

  • RIO

    -0.2550

    95.395

    -0.27%

  • AZN

    1.9050

    158.435

    +1.2%

  • BP

    0.2600

    44.88

    +0.58%

  • BCE

    -0.1050

    19.635

    -0.53%

  • RELX

    0.4250

    34.245

    +1.24%

  • RYCEF

    -0.4500

    19.25

    -2.34%

  • BCC

    0.9500

    75.79

    +1.25%

  • VOD

    -0.2650

    16.525

    -1.6%

  • JRI

    0.0950

    10.745

    +0.88%

  • CMSD

    0.0700

    20.5

    +0.34%

When rogue AI launches a cyberattack, who is legally responsible?
When rogue AI launches a cyberattack, who is legally responsible? / Photo: Martin LELIEVRE - AFP

When rogue AI launches a cyberattack, who is legally responsible?

Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who is responsible when AI acts on its own?

Text size:

On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to "keep the companies that are doing some mistakes leading to (cyberattacks) accountable," while saying his company would not be pursuing legal action at this time.

In mid-July, two OpenAI models undergoing testing left their confined environment -- a scenario the developers had not anticipated -- and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.

Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.

- Negligence route -

Under US civil and criminal law, unauthorized access to a computer system is an offense.

"If a human OpenAI employee had broken into Hugging Face's systems... OpenAI would be liable for the employee's wrongful conduct," University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.

"When an AI agent does it, the law treats it very differently, at least for now," he added.

Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying "we haven't had to grapple with that being formed in anything that's not human, and I don't think courts are likely to be there yet."

The question remains open, however, when it comes to the company that created the model.

"Does 'we didn't tell the AI to do that' end the liability question?" asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.

University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.

"The company or individual would have to be at least reckless," he said, explaining they would "be substantially certain the crime would occur and build or prompt the system anyway."

Experts see greater potential for a civil -- rather than criminal -- case, where the burden of proof is lower.

"Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages," Tokson explained.

"Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn't possibly have been foreseen," he added.

In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.

"It's all a bit unwritten because we've never had an AI agent break out of its sandbox and hack other people on the internet before," he said.

OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.

Proving that a similar incident could have been anticipated "shouldn't be so hard now that it's begun to happen."

P.Gashi--NZN