And if a rogue AI agent actually *causes* one of those more damaging attacks, what then? "To err is human, but to really fsck things up takes a computer" and all that?
What seems to be missing here isn't just any clarity in legislation about liability for AI agents, especially labs running frontier models who seem to get free legal passes that would absolutely not be afforded to regular plebs who - potentially entirely by accident - cause an agent to hack someone else, but any serious discussion about putting those legal frameworks in place is also lacking. Seriously, WTF is up with that? How many incidents that are clearly in breach of existing computer misuse legislation do we need to get some action here, either under existing laws (including, potentially, civil law) or to start working on tweaks to existing laws to provide some specific clarity relating who is liable for any misuse of AI agents?
I get the AI labs almost certainly have a tacit "don't sue us, and we won't sue you" agreement in place for things like this to try and avoid regulation they definitely do not want because their actions are quite obviously not aligned with the regulation they are claiming they want put into place. Third parties like South Korean banks are under no such terms however, and given they are in the financial sector (or health sector in another recent example) probably have legal obligations of their own as well, so again - why are we not even hearing of any talk of legal action?