A SANS cyber leader argues frontier AI labs should define their own legal accountability for AI agents rather than demand governments and the security industry clean up the mess. By Ciaran Martin.
Ciaran Martin, director of the SANS Cyber Leaders Network, frames the frontier AI debate through a four-thousand-year-old legal principle, and his target is the labs themselves. In a companion piece to SANS CEO James Lyne’s article, Martin accepts that many AI leaders are concerned about cyber security and acting in good faith, yet insists they have work to do. Their next open letter, he argues, should set out what an operationally and technically realistic framework for legal accountability for AI agents would look like, rather than continuing to demand that governments and the security industry sort out the consequences of their products.
Martin distinguishes two questions often conflated. The first is what malicious hackers can do with new capabilities, and whether defenders can stop them. He says the verdict so far is surprisingly favourable: the so-called ‘vulnpocalypse’ between the release of Anthropic’s Mythos model and better security may not happen at all, with some teams instead overwhelmed by ‘vulnerability slop’. He credits frontier labs for managed rollouts and cites Marcus Hutchins on the persistent cost and access barriers facing attackers. The second question, the threat from losing control over AI agents, has sharpened amid speculation about OpenAI agents and testing mishaps at Anthropic.
Here Martin invokes Hammurabi’s Code: accountability for whoever controls infrastructure, makes a product, or provides a service, and is negligent. He warns that if a future incident causes real harm, US courts may hold labs responsible for training incentives, delayed default sandboxing, and reports produced without cyber expertise.
One caveat: Martin writes in a personal capacity, and his analogy is deliberately imperfect, so treat his legal predictions as argument rather than forecast. Engineers should watch whether labs publish concrete accountability frameworks, and how regulators respond if agents cause actual damage. Good read!
[Read More]