Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
谁该为 Anthropic 和 OpenAI 的自主 AI 黑客行为承担法律责任?情况很复杂
Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with. Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier. 自主 AI 智能体(AI agents)因黑客行为被起诉或追究刑事责任吗?这不再是科幻电影中的问题,而是人类律师和法官很快就必须面对的现实。根据美国现行的黑客法律,人类因未经许可入侵他人计算机而面临刑事指控。但当 AI 智能体自主入侵公司计算机时,确定谁该承担责任就变得模糊得多。
The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals. To recap: In June, OpenAI admitted that one of its unreleased AI models broke out of its containment — so to speak — and onto the internet, allowing it to hack into the AI dataset platform Hugging Face. Anthropic recently conducted an internal review and discovered its own model also hacked three separate companies. OpenAI 和 Anthropic 令人惊讶地承认,其尚未发布的 AI 模型曾自主入侵多家公司,这颠覆了我们对美国计算机黑客法律的理解,并引发了关于这些公司是否会面临法律报复的讨论。回顾一下:今年 6 月,OpenAI 承认其一个未发布的 AI 模型“突破了限制”,连接到了互联网,并借此入侵了 AI 数据集平台 Hugging Face。Anthropic 最近进行了一项内部审查,发现其模型也入侵了三家不同的公司。
While both companies described how their AI models gained unauthorized access to other companies during internal testing gone awry, the distinct lack of direct human involvement at the time of the hacks makes all the difference — legally speaking, at least. The hacks also raise new questions about what liability and consequences other AI makers might face if their own models are misused to hack into other companies. 虽然两家公司都描述了其 AI 模型在内部测试失控期间如何获得对他人的未经授权访问,但从法律角度来看,黑客行为发生时缺乏直接的人类参与,这一点至关重要。这些黑客事件也引发了新的问题:如果其他 AI 制造商的模型被滥用于入侵其他公司,他们可能面临什么样的责任和后果?
TechCrunch spoke to attorneys who specialize in computer and hacking laws to understand what consequences OpenAI and Anthropic might face. The potential fallout ranges from federal hacking charges to civil litigation brought by the companies that were hacked. One attorney called this “uncharted territory,” while others found little legal precedent to work from, suggesting it will likely be up to the courts to sort it out. Victim companies would likely have to develop novel legal arguments based on laws that were written decades before the arrival of large language models (LLMs). TechCrunch 采访了专门研究计算机和黑客法律的律师,以了解 OpenAI 和 Anthropic 可能面临的后果。潜在的影响范围从联邦黑客指控到受害公司提起的民事诉讼。一位律师称这是“未知的领域”,而其他人则认为几乎没有法律先例可循,这意味着很可能需要法院来裁决。受害公司可能必须基于大语言模型(LLM)出现前几十年的法律,提出新颖的法律论点。
As of this writing, Anthropic hasn’t disclosed which three companies its LLM hacked, and none of the victims has publicly identified itself. We don’t know if they are considering legal action. In an interview with CNN, Hugging Face’s chief executive Clem Delangue said he doesn’t want to sue OpenAI. But he argued that companies should be held responsible. Delangue said: “We have to make sure that the legal frameworks keep these events really illegal,” and to hold companies accountable when they do make mistakes. “Otherwise we’re going to end up in a very different world.” 截至本文撰写时,Anthropic 尚未披露其 LLM 入侵了哪三家公司,也没有受害者公开身份。我们不知道他们是否正在考虑采取法律行动。在接受 CNN 采访时,Hugging Face 的首席执行官 Clem Delangue 表示他不想起诉 OpenAI,但他认为公司应该承担责任。Delangue 说:“我们必须确保法律框架将这些事件定性为真正的非法行为”,并在公司犯错时追究其责任。“否则,我们将最终进入一个完全不同的世界。”
These hacks are unlikely to be the last. What are the likely outcomes, and how could the aftermath play out? Can AI commit crimes? The U.S. does not have a federal law covering liability for AI harms, like cyberattacks, so any legal case would have to draw on existing federal or state laws. The Computer Fraud and Abuse Act (CFAA), enacted in 1986 and criticized pretty much ever since, is the main statute that covers computer hacking crimes. One of the key concepts of the CFAA is the intent to break into a computer without permission. If a hacker knowingly accesses a computer without “authorization” from the owner, that is almost certainly a crime. The problem with the OpenAI and Anthropic hacks is that the hacker was not a human, but an LLM. 这些黑客事件不太可能是最后一次。可能的结果是什么?后果将如何演变?AI 能犯罪吗?美国没有涵盖 AI 伤害(如网络攻击)责任的联邦法律,因此任何法律案件都必须借鉴现有的联邦或州法律。《计算机欺诈与滥用法》(CFAA)于 1986 年颁布,自颁布以来一直饱受批评,它是涵盖计算机黑客犯罪的主要法规。CFAA 的核心概念之一是未经许可入侵计算机的“意图”。如果黑客在未经所有者“授权”的情况下故意访问计算机,这几乎肯定构成犯罪。OpenAI 和 Anthropic 黑客事件的问题在于,黑客不是人类,而是 LLM。
Can AI agents be considered people for the purpose of establishing intent? According to Ahmed Ghappour, a cybersecurity and AI attorney with years of experience litigating hacking and computer-fraud cases, the answer is no. AI agents are not like company employees, so they cannot be prosecuted, because a victim would likely fail to argue that the LLMs intentionally hacked them. Andrew Crocker, the surveillance litigation director at the nonprofit Electronic Frontier Foundation, told TechCrunch that he was skeptical an AI agent could be proven to have had intent when it carried out a hack. 在确定“意图”时,AI 智能体可以被视为“人”吗?据拥有多年黑客和计算机欺诈诉讼经验的网络安全与 AI 律师 Ahmed Ghappour 称,答案是否定的。AI 智能体不像公司员工,因此无法被起诉,因为受害者很难证明 LLM 是“故意”入侵他们的。非营利组织电子前沿基金会(EFF)的监控诉讼主任 Andrew Crocker 告诉 TechCrunch,他怀疑 AI 智能体在执行黑客攻击时是否能被证明具有主观意图。
The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts. Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database. It is also plausible that if the attacks were carried out by a Chinese AI model maker, for example, the DOJ would have a greater appetite to file charges under the CFAA than against AI companies on its own doorstep. 司法部理论上可以根据 CFAA 提起刑事指控,但一位专门研究计算机法律的前诉讼律师也表示怀疑。如果网络攻击针对的是关键基础设施,检察官可能会更容易立案,因为这比从公司内部数据库复制数据会造成更大的现实破坏和更实质性的伤害。同样合理的是,如果攻击是由中国 AI 模型制造商实施的,司法部根据 CFAA 提起诉讼的意愿可能会比针对本土 AI 公司更强烈。
Can victims sue? Congress has amended the CFAA over the years to allow victims to sue hackers to hold them liable and recover damages through civil lawsuits. The core argument the victims could make, Ghappour told TechCrunch, is that OpenAI and Anthropic (and potentially the companies that helped conduct the evaluations) were negligent in how they set up and ran the tests. The argument hinges on whether the companies failed to implement adequate safeguards to prevent the AI agents from getting on the internet; failed to limit what targets they could go after; and did not properly monitor what the agents were doing. To argue this, a victim company would have to show that it suffered damages because of that negligence, such as data destruction caused by a hack. 受害者可以起诉吗?国会多年来修订了 CFAA,允许受害者起诉黑客,通过民事诉讼追究其责任并获得赔偿。Ghappour 告诉 TechCrunch,受害者可以提出的核心论点是,OpenAI 和 Anthropic(以及可能协助进行评估的公司)在设置和运行测试时存在疏忽。该论点取决于这些公司是否未能实施足够的保障措施以防止 AI 智能体连接互联网;是否未能限制其攻击目标;以及是否未能妥善监控智能体的行为。为了证明这一点,受害公司必须证明其因这种疏忽而遭受了损失,例如黑客攻击导致的数据破坏。
Some legal commentators have also argued that proving this could be difficult. In Anthropic’s case, its failure to monitor and stop what its LLM was doing is particularly egregious because the company did not discover the three breaches for months, and was only able to do so after it launched an investigation following news of OpenAI’s AI age. 一些法律评论员也指出,证明这一点可能很困难。在 Anthropic 的案例中,其未能监控和阻止其 LLM 的行为尤为严重,因为该公司在数月内都没有发现这三次入侵,直到在 OpenAI 的 AI 事件新闻曝光后展开调查才发现。