2026-09-16 20:20 UTC
Replies (1)
-
@DaveMWilburn@infosec.exchange 2026-09-16 20:26
@cigitalgem@sigmoid.social CFAA criminal violations require establishing criminal intent beyond a reasonable doubt. But the model itself likely lacks the capability to possess intent, and the humans that built it and gave it its instructions didn't intend for any nonconsensual hacking to occur. As far as civil violations go, recent SCOTUS case law gutted the ability of victims to recoup investigative costs, which are probably the biggest costs they incurred here. US federal law governing tech doesn't currently impose criminal or civil liability for negligence, recklessness, or lack of supervision. That has been intentional, out of the theory that it would deter innovation. Congress needs to readdress that, and there's also probably room for states to step in. Hopefully other countries also have stronger laws. But in the meantime, we're kinda fucked.