If I was caught trying to exploit a government site I'd be in trouble. Why no one is knocking the doors of these companies?
It seems to me that no human intended for these hacks to occur. So they were not illegal hacking. (IANAL, please correct me if this is inaccurate.)
I think it’s clear that OpenAI is liable for any damages, but the way that the (very broad and at times vague) anti hacking laws are written, accidental agent hacks seem to not be covered.
In this case, the "agent" had every intention of doing what it was doing.
I'm not claiming that "accidental hacking" (whether by human, or agent) is covered and illegal. I am claiming that calling this "accidental" is not a valid defense. One incident? Maybe. But this is pretty far past one incident.