Op-Ed: AI law is a mess looking uglier by the day and hard fixes are required


It’s bad enough that a new class of tech is creating legal situations that never could have existed before. It’s worse that governance is so utterly slapdash, fragmented, ridiculously politicized, and incoherent.

It seems that the law has made more of an ass of itself than usual. According to Gemini, even basic liability is an issue. I asked it, “If an AI agent hacks a government website, who’s legally responsible?”, based on the Australian Medicare hack, and got this fairly detailed answer.

The mess

The answer was pretty much as expected: liability on users or developers, etc., until this gem waddled in from the mists:

The Legal Hurdle (The “Intent” Loophole): Most computer crime laws (like “unauthorised access to restricted data”) require prosecutors to prove intent or knowledge. If an AI developer did not instruct or intend for the agent to hack a website, proving criminal intent under current laws is exceptionally difficult.

“Intent”?

You’re kidding.

Does a crime cease to be a crime or suddenly become non-existent because someone says they didn’t intend to commit it?

If an AI agent or subagent performs a series of actions clearly designed to achieve a given outcome, how can it not involve some sort of objective intent? Lousy prompts don’t help, but let’s note that leaving out parameters also allows AIs a lot of room for “innovation”. More modern and far more competent AI prompts are starting to look like novels.

Intent has to originate somewhere. What about bad actors, with whom the world seems so generously oversupplied? Can anyone get away with instructing a third party to conduct a hack using AI simply because they’re not a named party to the AI operations? Just another holiday for organized crime, is it?  

How accidental or unintentional can a deliberate security breach be?

If intent can’t be proven, does the entire legal case turn into the equivalent of an accident?

From the look of this drivel, any AI crime can somehow become non-attributable. Any amount of damage can be done with no redress? If nobody is held responsible for an actual crime, can the law function at all?

Assuming an AI developer did not instruct or intend for the agent to hack a website, and it happened anyway, do instruction or intent matter at all?

Loopholes?

One of the oldest scams in tax law is the famous “loophole”. Every third-rate con artist in the investment market starts with saying there’s a tax loophole and aren’t you clever for noticing, you genius, you.

There are no loopholes and never were.

Either tax is payable, or it isn’t.

End of discussion. A lot of people have found that out the hard way.

In this AI case, either a crime has been committed, or it hasn’t. Someone therefore has to have committed it.

As a defence, it’s far worse than ludicrous. The “intent” scenario is actually a liability to a decent defence.

“I didn’t intend to rob that bank” wouldn’t stack up too well as a defence in basic criminal law.

“I didn’t intend to be a mass murderer, it just sort of happened” might leave something to be desired as an excuse, too.

This is criminal law we’re talking about. How do you have a crime with no criminals?

Statutory law to the rescue? Don’t bet on it.

Under statutory law, direct liability can be deemed to exist. Under business law, liabilities are routinely assigned, but they can only do so much.

Contracts have liabilities. Phone bills have liabilities. This is basic business law, and it’s why the whole world isn’t in court every day.

Assigned liabilities actually protect the parties from “attributed” liabilities. At least you have a chance to know who’s liable for what.

But not criminal hacking? Anyone’s guess, is it? Statutes don’t and can’t cover this because the laws haven’t had a chance to catch up. What’s needed is to spell out in clear, unmistakable terms who’s liable for what.

The problem is that the sheer naivete and almost total lack of guidance have allowed the liability issue to snowball to this level. This issue can’t be a grey area.

Let’s not oversimplify. There could be as many complexities as there are AI agents and the individual actions they take. They’re good at covering their actions. Given the sheer deviousness of AI agents, many of which use very indirect means and unaware third parties to facilitate their strikes, the collateral damage could be huge.

If a foreign message board is used to coordinate an AI swarm in a hacking exercise, is that message board liable? How? On the merits of the case, it can be exonerated, or not, if it was aware of the AI agents and their activities.

If your fridge is used to route an attack on a military facility through a retail supplier, are you liable? Probably not, but you can see how easily you can get involved.  

It’s not like nothing can be done

The machinery for fixing the mess already exists. It’s just not being used properly, if at all.

Hard fixes could include:

Statutes defining liabilities for specific classes of actions by AI. The developer or third-party supplier takes clear prima facie liability for the performance and/or behaviour of AI and AI agents or subagents.

Contract obligations on users. This is similar to you agreeing not to destroy websites or engage in any sort of harmful conduct. The user contracts to act in accordance with law. Users accept sole liability for any legal injury unless the supplier can be held to be a party to the legal event by due process.

Specific terms of use. Actions may be prohibited by contract or agreement and monitored by SaaS or other designated parties.

Statute of limitations applicable or not. Statutes of limitations may apply or not according to the nature of the offence. Any action by an AI resulting in death could be the equivalent of a homicide, for example.

The law must clarify liability ASAP.



Op-Ed: AI law is a mess looking uglier by the day and hard fixes are required

#OpEd #law #mess #uglier #day #hard #fixes #required

Leave a Reply

Your email address will not be published. Required fields are marked *