The Ethics of Autonomous AI Agents for Offensive Security
TL;DR - This paper examines the ethics of autonomous LLM agents used for offensive security. It argues that their unpredictable behavior, open-ended impact, and low skill barrier could industrialize cyber offense and diffuse responsibility across users, developers, and third parties.
- Identifies three independent forms of indeterminacy: agent actions, real-world impact, and user population.
- Argues that opaque models and LLM supply chains hinder safety review, explanation, and incident attribution.
- Predicts a short-term advantage for attackers due to offense-defense cost asymmetry, despite possible long-term defensive benefits.
- Finds existing dual-use and AI-ethics frameworks inadequate and proposes stakeholder-specific recommendations.