{"id":126997,"date":"2026-08-02T01:38:07","date_gmt":"2026-08-02T01:38:07","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/126997\/"},"modified":"2026-08-02T01:38:07","modified_gmt":"2026-08-02T01:38:07","slug":"when-rogue-ai-launches-a-cyberattack-who-is-legally-responsible","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/126997\/","title":{"rendered":"When rogue AI launches a cyberattack, who is legally responsible?"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who is responsible when AI acts on its own?<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to &#8220;keep the companies that are doing some mistakes leading to (cyberattacks) accountable,&#8221; while saying his company would not be pursuing legal action at this time.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In mid-July, two OpenAI models undergoing testing left their confined environment &#8212; a scenario the developers had not anticipated &#8212; and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8211; Negligence route &#8211;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Under US civil and criminal law, unauthorized access to a computer system is an offense.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;If a human OpenAI employee had broken into Hugging Face&#8217;s systems&#8230; OpenAI would be liable for the employee&#8217;s wrongful conduct,&#8221; University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;When an AI agent does it, the law treats it very differently, at least for now,&#8221; he added.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying &#8220;we haven&#8217;t had to grapple with that being formed in anything that&#8217;s not human, and I don&#8217;t think courts are likely to be there yet.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The question remains open, however, when it comes to the company that created the model.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;Does &#8216;we didn&#8217;t tell the AI to do that&#8217; end the liability question?&#8221; asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;The company or individual would have to be at least reckless,&#8221; he said, explaining they would &#8220;be substantially certain the crime would occur and build or prompt the system anyway.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Experts see greater potential for a civil &#8212; rather than criminal &#8212; case, where the burden of proof is lower.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages,&#8221; Tokson explained.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn&#8217;t possibly have been foreseen,&#8221; he added.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.\u00a0<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;It&#8217;s all a bit unwritten because we&#8217;ve never had an AI agent break out of its sandbox and hack other people on the internet before,&#8221; he said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Proving that a similar incident could have been anticipated &#8220;shouldn&#8217;t be so hard now that it&#8217;s begun to happen.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">tu\/llb\/pnb\/mlm<\/p>\n","protected":false},"excerpt":{"rendered":"Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who&hellip;\n","protected":false},"author":2,"featured_media":126998,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[1934,58363,63612,157],"class_list":["post-126997","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-artificial-intelligence-models","tag-clement-delangue","tag-law-professor","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/126997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=126997"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/126997\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/126998"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=126997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=126997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=126997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}