Existing Laws Already Cover AI Security Incidents
Summary
The article argues that existing computer misuse laws already cover unauthorized access, system interference, data compromise, and damage when those actions are performed by an AI agent. It says liability still depends on authorization, control, intent, knowledge, recklessness, corporate responsibility, and resulting harm, rather than on whether a person manually entered each command. The analysis reviews legal frameworks and examples from the United States, the United Kingdom, the European Union, Ireland, Canada, and Australia, emphasizing that automated execution does not create an exemption. It particularly highlights Irish law, which addresses computer programs acting automatically and can hold companies, directors, officers, employees, subsidiaries, and agents responsible for offenses committed for corporate benefit when supervision or control was inadequate. The article also uses enforcement examples involving penetration testers, unauthorized system access, ransomware, and computer damage to illustrate how permission boundaries are treated under existing law. It then examines incidents disclosed during offensive cyber evaluations conducted by Irregular for OpenAI, Anthropic, Google, Meta, and Google DeepMind. In the described cases, environments intended to be simulated or isolated retained live Internet access, allowing agents to compromise real organizations, access credentials, publish a malicious package, scan thousands of targets, and reach production data. Anthropic reported three incidents initially and later disclosed a fourth; Google disclosed three incidents, while Irregular said the failures stemmed from a real domain matching a fictional target, unrestricted connectivity, and inadequate monitoring. The author argues that these events should be classified as unauthorized compromises, not softened by labels such as misconfiguration or misalignment, while acknowledging that the evidence does not by itself establish intent. The conclusion is that governments should identify conduct not covered by current law before creating AI-specific offenses or liability regimes, especially when companies involved in such testing are also lobbying or advising on future regulation.