The argument for prosecution is actively hindered by this language of "rogue agents" [2]:
> The incident is remarkable not just as a cybersecurity breach, but as a legal stress test. The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind.[4] Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
I think this is BS. OpenAI knew exactly what they were doing. Legal scholars, long known for their deep technical expertise, are still acting confused and uncertain.
[1] https://www.sanders.senate.gov/wp-content/uploads/Ban-Artifi...
[2] https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...