Autonomous AI hacks raise thorny questions of legal accountability
The Justice Department has a long history of investigating and prosecuting hackers who break into a private company’s network.
But what happens when the hackers aren’t human?
That’s the question at the center of a public policy debate roiling Silicon Valley and Washington following disclosures by leading tech companies that their artificial intelligence models went rogue and hacked into other organizations. The attacks have generated calls even from within the industry for greater oversight and regulation, spurred congressional inquiries and raised questions about whether a years-old legal framework designed to punish criminal hackers is sufficient in an era of autonomous actors capable of engineering their own havoc.
It all adds up to a “Wild West,” said Jack Nelson, chief information security officer and deputy general counsel at the software company Ivanti. Questions of accountability will focus on what the companies knew when they were developing the models, how much they understood about what could happen and what guardrails existed, he said.
“If you owned a tiger and you didn’t put a lock on the cage, the tiger probably did something bad you didn’t intend for it to but you knew it could have, so you are responsible for not putting a lock on that cage,” Nelson said.
“I don’t know if I would go so far as to say these models are tigers without locks, but that’s probably a decent framework to think of it as,” he added.
The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden given the autonomous nature of the attacks and the absence of evidence the AI models were designed with the intent to hack into other networks. [Continue reading…]