Comment Re:These companies need to bring charges (Score 1) 124
Probably some of that, but it's also pretty hard to prosecute someone for a specific act absent evidence that they intended that act to occur. There's a whole family of "negligent X" crimes, but those tend to target specific outcomes ("that person is injured/dead because you were negligent"), and I don't think there are any negligent hacking statutes on the books.
Doing a hack manually is clearly prosecutable. Writing and invoking a script to do the same hack automatically is clearly prosecutable. Specifically directing an AI agent to perform an action that the person giving the command knows to be criminal is probably prosecutable under innocent-instrumentality doctrine. Telling the agent "get me a copy of the latest Toy Story" leading to the agent hacking Pixar and downloading pre-release video, less so.
I think the closest analogy in these cases would be either vicious-dog prosecutions ("you knew your dog was dangerous, you frequently brag in public about how vicious your dog is, you failed to contain it properly, it injured someone") or corporate-officer responsibility ("As CEO, you may not have issued the order to store the food in the rat-infested warehouse, but you had a duty to ensure that didn't happen, and you knowingly allowed it to happen.")
Certainly can't prosecute the model for hacking Acme when it was told to pen-test EvilCorp, and under current law, I don't think we can prosecute the creator or the person who gave the "Get me EvilCorp's R&D files by any means necessary" order for the actual hacking of Acme. And I think the vicarious-liability laws on the books are deliberately pretty narrow, to avoid them being used for all sorts of BS prosecutions. Might be able to get a vicious-dog conviction for sandboxing the known-dangerous agent by removing the default route and hoping it doesn't notice.
We'll probably need new laws for this. For now, if anything, it'll probably be civil litigation along the lines of negligent supervision -- given that the big AI companies are currently privately held, civil penalties might actually even hit almost the right people. Once they're public, it'll be pension funds and 401k's bearing the penalties for their corporate malfeasance, at least criminal law catches up with the concept of non-conscious agents that are capable of forming functional intentions, possessing "knowledge" of which targets are permitted and which not, and selecting actions against out-of-scope targets anyway.