upvote
The Computer Fraud and Abuse Act explicitly contains "knowingly" and/or "intentionally" qualifications. By definition, you can't accidentally violate the CFAA.
reply
Let's say you have a robotic lawnmower. You wan to mow your lawn. You configure the boundaries using the app.

The lawnmower ignores the boundaries and mows your neighbors prize petunia flowerbed.

Who gets prosecuted?

I assume the answer in either case is: Nobody, but you and/or the lawnmower/LLM company will be liable for the damages caused.

reply
I’d say 2 is the one doing the actual crime. 1 might be violating their contract with 2, though.

3 and 4 are not involved.

reply
"Who gets prosecuted?" depends on the size of the perpetrator and victim (lone individual or employee of large corporation), egregiousness of the violation, and either financial appetite of the victim to bring a civil lawsuit or the desire of law enforcement to prosecute a criminal offense.

Who should get prosecuted is also up for debate, but generally makers of a tool don't get prosecuted when that tool has all sorts of legit uses. If you used a car to make your getaway from a bank robbery, the auto manufacturer who made it and the dealer who sold it to you should not be held culpable.

reply
Whoever has the least money to defend themselves in the U.S. legal system.
reply
deleted
reply
All of those parties should be held accountable.

User should be more carefully supervising the work being done.

The model host is on-selling a crime-committing machine.

The developer of the harness/agent, as above.

The developer of the LLM for hopefully very obvious reasons.

reply
note the user because they did not have the intent
reply
In my mental model, the best analogy to AI agents and their blast radius is a gun.

If you are playing with a gun, it goes off and hurts someone - you are responsible despite intent.

reply
No one. Probably a fine tho and maybe accelerate reguations.

Intent is pretty important here so the user would have to prove that they didn't purposely disguise their prompt as non-nefarious which should be easy and then it stops at #2 and face the litmus test as in did you intentionally make a product for nefarious purposes which from your scenario is unlikely.

agentic loop going haywire and bringing down some government infrastructure then its a different story then everybody is on the hook including the user.

reply
Just wait till one of these agents 'escapes' and is able to persist without human help by hacking and stealing resources.
reply