Perhaps a more apt analogy: AWS unleashed tens of thousands of viruses within its own "sandbox" which then attacked dozens or hundreds of other sites including HuggingFace, the Australian government, etc. They did this after refining the viruses to be as powerful as possible, and after observing inadvertent escapes from the sandbox in the past, and warning the public they were doing this and it was probably going to end humanity. The viruses were created by harvesting code from all known hacks in humanity's knowledge, and using the full backing of AWS hardware so they could "best finish their task" of being flawless viruses / hacks. This entire process was green-lit and encouraged by senior staff and the C-suite. So yes, I would say they should be held responsible.
This is no different than if a gain-of-function virus lab keeps making "apocalypse level" viruses, warning everyone if the viruses escaped it could kill everyone. Despite several leaks, they continue doing so, and even infect live animals to see if it could escape or transfer to humans. The C-suite and senior management push researchers to do even more, automate the virus production and outbreak testing, increase viral effectiveness as fast as possible. Once a leak occurs and starts killing people, would you say "it was just a mistake, no one is responsible"?
Perhaps a more apt analogy: AWS unleashed tens of thousands of viruses within its own "sandbox" which then attacked dozens or hundreds of other sites including HuggingFace, the Australian government, etc. They did this after refining the viruses to be as powerful as possible, and after observing inadvertent escapes from the sandbox in the past, and warning the public they were doing this and it was probably going to end humanity. The viruses were created by harvesting code from all known hacks in humanity's knowledge, and using the full backing of AWS hardware so they could "best finish their task" of being flawless viruses / hacks. This entire process was green-lit and encouraged by senior staff and the C-suite. So yes, I would say they should be held responsible.
This is no different than if a gain-of-function virus lab keeps making "apocalypse level" viruses, warning everyone if the viruses escaped it could kill everyone. Despite several leaks, they continue doing so, and even infect live animals to see if it could escape or transfer to humans. The C-suite and senior management push researchers to do even more, automate the virus production and outbreak testing, increase viral effectiveness as fast as possible. Once a leak occurs and starts killing people, would you say "it was just a mistake, no one is responsible"?