Ok, but if the agent's reasoning log says "The best way to get into Hugging Face is to find and exploit a zero-day vulnerability", surely those responsible for monitoring its actions should be criminally liable.
These guys would be screwed if they were operating under the EU AI Act.
And they absolutely should be regulated. This whole scenario is insane. Hugging Face are being far more generous in their response to this than I would be
I'm not putting my head under. How do we know this won't cause aneurysms? Damage eyes and ears? Getting a medical device approved takes time because of concerns like this.
These guys would be screwed if they were operating under the EU AI Act.