Triggering a remote exection vulnerability accidentally is exceedingly unlikely to cause any serious damage anyway; that’ll just crash the process. Proper exploits do not happen accidentally. If the software has a bug that makes an accidental action cause damage then liability is (or at least should be) on whoever hosts or distributes that program.
In some other cases the intent might actually matter. It’ll require major rewriting of legal code anyway, if you want the intent of an AI to be something that can be considered here.
Triggering a remote exection vulnerability accidentally is exceedingly unlikely to cause any serious damage anyway; that’ll just crash the process. Proper exploits do not happen accidentally. If the software has a bug that makes an accidental action cause damage then liability is (or at least should be) on whoever hosts or distributes that program.
In some other cases the intent might actually matter. It’ll require major rewriting of legal code anyway, if you want the intent of an AI to be something that can be considered here.