Comment Re:Enough is enough (Score 2) 59
Sorry, I missed the Australia part. Australia's Part. 10.7 isn't that different for the most part. It does contain a "recklessness" clause in addition to direct intent (unlike the US), but they define recklessness as requiring the accused to have a "subjective awareness" of "substantial" and "unjustifiable" risk of the specific charged event in question occurring, and choosing to take them anyway. This is defined as distinct from negligence, which is based on the much lower "reasonable person would recognize the risk" standard. Under recklessness (the one that can be charged in Australia), OpenAI employees wouldn't have had to 100% intend to hack HuggingFace, but they had to have thought there was a high chance that their models would choose to hack HuggingFace when they gave them a benchmark to complete. No prosecutor is even going to try on that one, esp. given that the models also attacked OpenAI itself and were wreaking all sorts of havoc against OpenAI's own internal processes.
Once again, though: civil liability is ample remedy. Nobody thought "there's a good chance it'll hack HuggingFace if we tell them to do a benchmark in a sandbox", but you shouldn't have any trouble at all showing that these companies full of people from the Rationalist movement (practically an AI-apocalyptic cult) think that their models are dangerous in general, yet nonetheless were negligent in terms of keeping them from escaping (outright no monitoring!) or properly monitoring their training to ensure that they weren't training them to cheat, so that they wouldn't try in the first place.
(And I feel the need to reiterate that US cybercrime law, the one in question for most of the hacking cases, has no standalone recklessness standard)