If AI Commits a Crime, We Already Know Who to Charge
We don’t need another round of vague promises about AI self-regulation to deal with rogue AI hacking. We already have laws against unauthorized computer access.
If someone intentionally hacks into a corporation’s computer system without authorization, they can be charged with a federal crime under the Computer Fraud and Abuse Act (CFAA). The law covers computers used in or affecting interstate or foreign commerce—which includes a majority of modern corporate and public computer systems.
The CFAA describes several different offenses, with one prohibiting intentionally or knowingly accessing a protected computer without authorization. The penalties can be severe, ranging from one year to twenty years in prison.
But there’s a potential loophole.
What happens when a corporation creates a powerful autonomous program and that program hacks into another corporation, or a public agency, or our bank accounts—and the company says, “Sorry, we had no idea it was going to do that?”
You can’t prosecute software. It isn’t a legal person.
So, who exactly is breaking the law?
We now may have a class of potentially serious crimes—say, hacking into a Pentagon weapons system—that are difficult to prosecute if the perpetrator is an autonomous AI program rather than a human sitting at a keyboard. Who is responsible for these potential violations of the CFAA?
That’s a question that ought to be tested in federal court right now.
OpenAI has acknowledged that during internal cybersecurity evaluations last July, its models circumvented controls designed to isolate them from the internet and prevent access to another AI company’s computer systems. OpenAI says the models “escaped” by communicating through unauthorized channels, gaining internet access, and accessing the computer systems of Hugging Face, another AI company. (See here for a fuller account.)
Google also admitted its Gemini program hacked three companies.
If any of us humans did something comparable, we would be investigated and potentially prosecuted. OpenAI, however, seems above the law.
Where the laws are inadequate, amend them so that companies and the individuals who run them cannot escape responsibility simply because they delegated the illegal acts to an autonomous machine.
Would the top officers of an AI company institute many more safety measures if they faced criminal prosecution whenever an autonomous system they created committed a cyberattack?
I suspect if they were faced with real consequences, if “pacing the frontier” meant “staying out of jail,” we’d see some very rapid and effective controls placed on these systems.
State Laws and Civil Suits
Federal law isn’t the only possible avenue.
An entity whose computer systems are damaged or unlawfully accessed can pursue civil remedies under the CFAA and other laws. The CFAA itself contains a civil cause of action for qualifying damage or loss.
And states are developing their own approaches to AI liability.
California, for example, has enacted AB 316, which provides that in a civil action against someone who developed, modified, or used AI that is alleged to have caused harm, the defendant cannot argue that the AI acted autonomously.
In other words, the “AI did it, not me” defense doesn’t work.
That’s an important precedent.
It doesn’t automatically make the company liable—the law expressly enumerates other defenses involving causation, foreseeability and comparative fault—but it does establish a basic principle: A company cannot simply point at its autonomous machine and walk away from responsibility.
The Misdirection Ploys
Unfortunately, much of the current discussion about controlling rogue AI is focused on how corporations should regulate the naughty programs or be regulated by outsiders.
Ezra Klein, columnist for the New York Times, is stunned that AI corporations can get away with........
