
Brussels is also on a quest to slash more tech regulation in an effort to "simplify" rules to help businesses grow. AI-specific liability rules were suggested by the European Commission in September 2022, but the Commission withdrew them last year.
Legal protections
The bloc’s existing regulation already includes a view of AI through the lens of product safety. It pushes companies to assess their AI models or applications and determine the risk they pose to the audience: unacceptable, high, limited, or minimal.
But the law does little to address the damage done.
The law also doesn’t cover AI models before they’re deployed, during training or testing, even though most hacks last summer were conducted by agents powered by internal-only research models.
“The way it works right now basically grants no rights to people who are harmed by artificial intelligence,” said Mario Mariniello, senior fellow on digital and competition issues at think tank Bruegel. "It reduces the incentives for developers to factor in that risk and therefore invest into safety."
Cybersecurity experts point to this summer’s incidents, such as the incident in which OpenAI-powered agents hacked into Hugging Face, as evidence of the need for a liability scheme.
“I don’t think that it’s a good path to go on to say that because there was no criminal intent and the AI agent did it, there is no legal liability,” said Marcus Hutchins, a U.K. cyber expert who is best known for stopping a global outbreak of WannaCry software in 2017.
Some experts, like associate professor Irene Kamara at Tilburg University, pointed to the fact that AI agents are often anthropomorphized, as if these are human-like protagonists launching an attack by their own: It "shifts the focus away from looking for the actual responsible individual(s) or persons behind the incident,” she said.