back

by matheusmoreira·11d ago·view on hn ↗
Shouldn't the very act of sandboxing the AI be enough of a defense against criminal negligence?

Maybe they use the best sandbox available and the AI hacks through it anyway by discovering some zero day or something. They still demonstrated enough prudence to at least attempt to sandbox the AI.

Criminal negligence would be "nah nothing's gonna happen" followed by YOLOing it then going home for the weekend.

2 comments
Generally, yes, sandboxing would be a defense, because criminal negligence (again, it's state specific, so this is a law-school-level generalization) requires "gross deviation from the standard of reasonable care". So a mistake in judging the kind of sandbox or isolation you need would not be criminal negligence unless that mistake fell into the above category. I can't think of a case where it would or has - courts have consistently held mistake of judgement to be below criminal negligence in every case i'm aware of. I'm sure it's happened somewhere though.

As i mentioned elsewhere, the standard is basically "total disregard for safety in the face of an obvious and huge risk that resulted in injury or death". I don't think anything we are talking about here comes close to these criteria.

Thank you for your perspective as a lawyer!
Maybe. However they used a flaws sandbox when they could have physically not connected any computer to the internet (including wifi)
The existence of alternatives would generally not be enough for criminal negligence.

Making mistakes of reasoned judgement are basically never criminal negligence.

In every state i'm aware of, it would require total disregard for safety in the case of a huge and obvious danger.

It would also have to cause injury or death.

The bar for criminal negligence is pretty high.

We need details of the exact facts before we can say if they met any bar. Was their sandbox something from 2005 that has a ton of known holes, or something modern?

There are two sides of this.

First the AG are checking to see if they really took enough care or not. If they didn't then I expect criminal negligence. Even if they took care I want them to feel some pain from the investigation because their care wasn't enough to work.

Second I want them to verify the laws are correct. This is a new area and there might be loopholes that need to be closed. Regardless of the law, there was a successful attack and that should not be allowed.

I still don't understand exactly which facts you think any of this would change and cause it to be criminal negligence.

I will state a fairly blunt position: Unless literally nobody thought or tried at all here, i would give it a 0% chance of meeting the bar of criminal negligence.

The rest is a distinction without a difference.

As for what you want them to do - i don't agree the investigation should cause them to feel pain - that's not a good goal for investigations, and definitely not one we should want, because it essentially presumes they did somethign wrong in the first place. A bad outcome does not mean a broken process. All processes have error bars. You can desire the error bars to be smaller, and try to back that up with criminal penalties, but an expectation that error bars will be 0 makes no sense.

You can do absolutely everything right and still have people die - star trek was not wrong in that regard. Punishing that will not fix this inconvenient reality, which is why we generally don't punish it. This is also why we distinguish between inherently dangerous activities and not, for example.

As for the laws, sure, i think it's totally reasonable to explore whether you want the law to be different, but again, i totally disagree with your second part.

A successful attack does not imply anything is actually wrong with criminal law, or should be changed. The question is more of what error bars you want on the activity and where what they did falls - inside or outside those error bars.