I think this is the solution to a lot of AI 'alignment' issues.
We have laws, and LLMs should NEVER break them unless the user states its fine with some qualifying condition. Yes, every country has a different legal system, but I think there's a decent idea of what constitutes intrusion thats agreed on in most parts of the world.
In grey area scenarios, the user should be able to override this, with a warning of clear consequences of, and should they accept, users should be held criminally liable.
If the LLM does so unprompted, the responsibility should be the providers'.
LLMs should be considered tools, legally speaking.