Replying to
@zackwhittaker@mastodon.social @lorenzofb@infosec.exchange I don't see why i's a tricky question. An LLM is just a piece of software that the operator does not fully understand and failed to configure appropriately.
If I used a traditional vulnerability scanner (a tool that I sorta but do not completely know exactly what it's doing) and I make a mistake and it interferes with another person's system, I am clearly responsible. The same should lie with the operator(s) of an LLM.