When liability for an action depends on intent, we evaluate whether the AI had intent, even if no-one at the company did so.
To give some examples:
In the above scenario we would treat it as though OpenAI itself hacked Hugging Face.
Do you know what the current legal status of OpenAI incident would be? That is, if Hugging Face decided to sue OpenAI for hacking into its systems, would they be likely to prevail?
Holding the company that created an AI (or any other software) liable for its actions indeed seems like the only sensible policy, but I’m not an expert in the law here.
If Hugging Face wanted to be jerks about it, they could sue for the costs of cleaning up from the breach, e.g., hiring a cyber forensics firm to make sure the model didn’t leave any backdoors or other lasting damage on their systems. They aren’t doing this because technically sophisticated firms prefer to maintain a cooperative stance on this kind of thing when possible, as it keeps them more secure in the long run by incentivizing others to share relevant information with them.
If a model does something illegal, make it illegal to deploy that model family for a period of time (duration depending on the crime --> loss of profits from OpenAI --> incentivizes them to make very safe models), and require rehabilitation (fine-tuning) that passes some safety threshold.
This could apply to open-weight and closed-weight models.
Do you know what the current legal status of OpenAI incident would be? That is, if Hugging Face decided to sue OpenAI for hacking into its systems, would they be likely to prevail?
Holding the company that created an AI (or any other software) liable for its actions indeed seems like the only sensible policy, but I’m not an expert in the law here.
Hugging face couldn’t do a civil suit because they haven’t been meaningfully harmed.
Federal prosecutors couldn’t do a criminal suit, because there was no intent from open AI, which is required to prosecute cyber security crimes.
If Hugging Face wanted to be jerks about it, they could sue for the costs of cleaning up from the breach, e.g., hiring a cyber forensics firm to make sure the model didn’t leave any backdoors or other lasting damage on their systems. They aren’t doing this because technically sophisticated firms prefer to maintain a cooperative stance on this kind of thing when possible, as it keeps them more secure in the long run by incentivizing others to share relevant information with them.
Limited liability makes this extremely tough.
Attack the profits.
If a model does something illegal, make it illegal to deploy that model family for a period of time (duration depending on the crime --> loss of profits from OpenAI --> incentivizes them to make very safe models), and require rehabilitation (fine-tuning) that passes some safety threshold.
This could apply to open-weight and closed-weight models.