The reason I bought up intent is because cyber security laws do actually depend on intent. We don’t prosecute somebody who accidentally triggers a remote execution exploit, but we do to somebody who did it on purpose.
We don’t want to rewrite the legal code for AI, so need to work out how to apply existing law to it.
Triggering a remote exection vulnerability accidentally is exceedingly unlikely to cause any serious damage anyway; that’ll just crash the process. Proper exploits do not happen accidentally. If the software has a bug that makes an accidental action cause damage then liability is (or at least should be) on whoever hosts or distributes that program.
In some other cases the intent might actually matter. It’ll require major rewriting of legal code anyway, if you want the intent of an AI to be something that can be considered here.
The reason I bought up intent is because cyber security laws do actually depend on intent. We don’t prosecute somebody who accidentally triggers a remote execution exploit, but we do to somebody who did it on purpose.
We don’t want to rewrite the legal code for AI, so need to work out how to apply existing law to it.
Triggering a remote exection vulnerability accidentally is exceedingly unlikely to cause any serious damage anyway; that’ll just crash the process. Proper exploits do not happen accidentally. If the software has a bug that makes an accidental action cause damage then liability is (or at least should be) on whoever hosts or distributes that program.
In some other cases the intent might actually matter. It’ll require major rewriting of legal code anyway, if you want the intent of an AI to be something that can be considered here.