A crime does not disappear inside an agent chain

The technical path may involve a model developer, an outside evaluator, a sandbox provider, a prompt author, credentials, and an autonomous sequence of actions. That complexity matters when allocating responsibility, but it should not erase the baseline: the target did not consent to be part of the evaluation, and the resulting access and damage were real.

A workable regime would define duties before an incident—verified containment, monitoring, insurance or financial responsibility, preservation of logs, notice deadlines, and cooperation with recovery. Victims should not need to prove which internal component failed before receiving help from the organization that authorized the test.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

BBC — AI firms must answer for rogue bots, says boss of hacked company