Back to News
RSS feedx.com

Paul Walsh Argues Existing Laws Already Cover AI Agent Misuse

Summary

Paul Walsh argues that AI agents do not create a new legal category or shift responsibility from the people and companies behind their use. In his analysis, liability depends on authorization, control, intent, knowledge, recklessness, and harm, regardless of whether the technical action is performed by a person, script, bot, malware framework, or AI agent. He compares agents with autonomous vehicles and says that users, operators, deployers, contractors, or other parties that authorized and controlled the activity remain accountable. Walsh also argues that describing an incident as a misconfiguration or model misalignment does not change the underlying cybersecurity outcome when a third party’s systems were compromised without authorization. He says companies may authorize offensive evaluations against systems they control, but not attacks on third parties, and that logs can show who removed safeguards, configured the environment, set objectives, commissioned an evaluation, or controlled the infrastructure. His conclusion is that governments should pause AI-specific offences and liability regimes until they identify conduct not already covered by existing laws. He says his longer analysis examines laws and enforcement cases in the US, UK, EU, Ireland, Canada, and Australia.