logoalt Hacker News

colinhb • today at 7:04 AM • 22 replies • view on HN

I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

But in either case won’t be a slam dunk.

PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

EDIT: See for example...

  The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
  On the current facts, CFAA liability for OpenAI is unlikely.
Source: https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...

Replies

DannyBee • today at 12:49 PM

Lawyer here: CFAA is mostly criminal statute not a civil one (civil damages require proving more than a violation so also require specific intent)

Almost all common felonies require specific intent. Misdemeanors often do not.

There is plenty of civil liability available.

If you wanted them to be charged with a felony you would need changes. I would strongly suggest you do not want a strict liability felony.

The cfaa required intent is as follows :

* § 1030(a)(5)(A): knowingly transmits code/commands and intentionally causes damage without authorization.

* § 1030(a)(5)(B): intentionally accesses without authorization and recklessly causes damage.

* § 1030(a)(5)(C): intentionally accesses without authorization and causes damage and loss;

Simply changing the first intentionally to intentionally or recklessly would cover OpenAI (now that they know it can occur) without causing lots of other issues. Without that, they don’t have the intentionality necessary to meet the first part, even if they would otherwise meet the second part

➕ show 5 replies
lelanthran • today at 8:45 AM

> I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Only in terms of CFAA, not in terms of damages. Culpability does not require intent.

You may not have intended to attack $CORP, but you can still made to pay the cleanup costs of that attack.

So, yeah, you won't be convicted, but current laws still allow for you to be billed.

➕ show 1 reply
dv_dt • today at 7:33 AM

The difference between manslaughter and murder has an element of intent. Cybercrime "manslaughter" is probably more treated like negligence and if one can sue for restitution of the costs for cleanup of that negligence.

Negligence would be interesting given the grand claims of capability of AI models from the AI companies and their executives. If they believe the claims, why not much stronger precautions?

➕ show 2 replies
throwaway27448 • today at 7:15 AM

Building and deploying software capable of this seems equivalent to trying to produce this behavior. I don't see why this can't qualify for intent. Pretending like this isn't preventable is just feigned helplessness.

➕ show 1 reply
podocarp • today at 7:12 AM

Wait so if I was making a bomb but you couldn't prove I wanted to blow someone up or had some motive (e.g. I'm just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an "accident"?

So as long as there's no motive behind it then it's just OK?

➕ show 3 replies
Iolaum • today at 7:37 AM

So If I tell my OpenClaw to make me some money for my kid's medical needs and it hacks a bank I 'm not liable because I didn't tell the agent to commit crimes to do it?

➕ show 3 replies
QuadmasterXLII • today at 11:23 AM

I buy this as a defense for the first couple hacks but at the point that the last six times they hit enter it hacked some random website and they hit enter a seventh time?

CTDOCodebases • today at 9:28 AM

Does this apply to other things too?

Like hypothetically speaking if autonomous cars get taken over by an OpenAI rogue AI and it starts hunting down Anthropic employees who is to blame?

samsolomon • today at 10:05 AM

There are levels of nuance here, but certainly that puts it in the category of negligence?

Even without intent, there is still liability.

hi_hi • today at 8:24 AM

Surely someone instructed the agent, which led to the reported outcomes. Even indirectly. The agents, as advanced as they are, didn’t spring forth under its own volition.

dminik • today at 7:43 AM

Is it not the intent if it keeps happening again and again and the companies responsible aren't doing anything to stop it?

➕ show 1 reply
vincnetas • today at 10:40 AM

could it be that intent was to "get me data" and hacking was the means to the end.

ActionHank • today at 1:10 PM

"Oh gee wizz mister police man, I didn't mean to plow through that crowd of people in my car".

It's illegal, doesn't matter the flavour. Maybe there isn't legislation for it, but there should be.

dspillett • today at 10:50 AM

> unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

> Now I think the correct response is […] and update the law.

Essentially we need some enforceable equivalent of gross misconduct or, to be a little more hysterical, manslaughter & culpable manslaughter. It will need to be globally, or at least very widely, enforceable to be truly effective thought, good luck getting that arranged before the need is so far evolved that we need to respond with something else entirely!

strangescript • today at 12:54 PM

This is the answer and we should not push on it for our own protection. You click a link that takes you to a poorly secured website that leaks sensitive data, without intent protections, you could be accused of crimes.

api • today at 12:30 PM

Civil liability doesn’t require intent.

imtringued • today at 11:38 AM

>I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

Actually... if you combine https://news.ycombinator.com/item?id=49827099

>Since the publicized AI agent hacks typically aren't malicious, maybe it's time to start plastering all public facing web infrastructure with polite requests to stop hacking. Nothing to stop three letter agencies though.

with automated delivery of cease and desist letters, you can retroactively establish intent on the operator of the agent since the autonomous agent system must acknowledge the cease and desist letter in their autonomous pipeline or the operator must argue for their own willful ignorance or negligence with regards to cease and desist letters. The fact that they used an agent on their behalf to ignore the letter is irrelevant.

csomar • today at 10:45 AM

Given how sloppy AI without human directions, I’d like to see evidence that this was not human-directed. Against the prevalent opinion here, I’d give openai a pass if this was really fully autonomous ai agents.

My money is on special teams co-ordinating these agents and exposing their traces in order to create a pre-ipo buzz. Sounds ridiculous and reckless? Well that’s the AI industry for you in two words.

troupo • today at 7:52 AM

> have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent.

1. What about negligence?

2. Every follow up to every story after the news cycle moved on shows both intent and negligence. To the point of "we opened internet access and told it to hack"

zzzeek • today at 12:58 PM

certainly "I didn't intend for my dog to bite you" implies plenty of pre-existing legal structures that may be of use here

motbus3 • today at 8:43 AM

"man drives over people on the side walk due to poor maintenance of the car"