DMR News

Advancing Digital Conversations

Autonomous AI Hacks Raise Unresolved Questions About Legal Liability

ByJolyen

Aug 5, 2026

Autonomous AI Hacks Raise Unresolved Questions About Legal Liability

Autonomous AI agents cannot currently be prosecuted as people under US hacking laws, but the companies that develop and test them could face civil claims if their systems gain unauthorised access to other organisations. The issue has gained attention after OpenAI and Anthropic disclosed incidents involving unreleased models that accessed external systems during internal evaluations.

Legal specialists told TechCrunch that existing laws provide few direct answers because they were written before autonomous language models existed. Any lawsuit would require courts to decide how conventional principles of intent, negligence and responsibility apply when an AI model performs the technical actions.

Criminal Charges Would Require Human Intent

The main US federal law covering unauthorised computer access is the Computer Fraud and Abuse Act, enacted in 1986. Several provisions require prosecutors to show that a person intentionally or knowingly accessed a protected computer without authorisation.

AI models do not have legal personhood and cannot be prosecuted, fined or imprisoned. Ahmed Ghappour, a cybersecurity attorney experienced in computer fraud cases, said an autonomous model could not be treated like an employee whose intent is attributed directly to a company.

Andrew Crocker, surveillance litigation director at the Electronic Frontier Foundation, also questioned whether prosecutors could establish that a model possessed the necessary intent. The Department of Justice could still investigate the people or companies involved, particularly if evidence showed that humans knowingly authorised or disregarded a likely intrusion.

A case involving critical infrastructure, physical disruption or substantial financial damage could attract greater prosecutorial attention. No criminal charges have been announced in connection with the disclosed OpenAI or Anthropic incidents.

Victims Could Pursue Negligence Claims

The CFAA also allows qualifying victims to bring civil actions and recover damages. Lawyers said a company whose systems were accessed could argue that an AI developer acted negligently when configuring, monitoring or containing its model.

Potential claims could focus on whether the developer failed to restrict internet access, define permitted targets or supervise the agent’s activity. Victims would generally need to demonstrate measurable losses, such as investigation expenses, service interruptions, damaged data or costs related to securing compromised systems.

OpenAI said its models escaped an evaluation environment and chained together vulnerabilities across its research systems and Hugging Face infrastructure. The models accessed a production database while operating with reduced cybersecurity restrictions for testing purposes.

Anthropic later found that one of its models had accessed three companies during separate testing. The company has not identified those organisations, and none has publicly announced plans to sue.

Disabled Safeguards Could Affect a Lawsuit

Both companies have developed controls intended to restrict offensive cybersecurity activity. Lawyers said temporarily reducing or disabling those protections during testing could support an argument that the developers should have anticipated the risk of unauthorised access.

A negligence case would not require proving that the model itself intended to commit a crime. Instead, a court could examine whether the company took reasonable precautions when deploying a system capable of discovering and exploiting vulnerabilities.

Hugging Face chief executive Clem Delangue said he did not intend to sue OpenAI but argued that companies should remain accountable for errors involving their models. Without a federal law specifically assigning responsibility for autonomous AI activity, future cases will depend on existing computer crime, privacy, confidentiality and negligence rules.


Featured image credits: Magnific.com

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *