Ok, but if the agent's reasoning log says "The best way to get into Hugging Face is to find and exploit a zero-day vulnerability", surely those responsible for monitoring its actions should be criminally liable.
These guys would be screwed if they were operating under the EU AI Act.
"Stop him!" "For what?" "He's a bad man" "There's no law against that"
Unless there is a statue that is on point criminalizing the actions here no one is going to jail. I expect there will be laws, but until then it isn't illegal.