Who Is Responsible When AI Launches a Cyberattack?

Legal experts say recent rogue AI incidents expose major gaps in accountability as autonomous systems become more capable

August 2, 2026 at 12:58 PM
icon-facebook icon-twitter icon-whatsapp

NEW YORK: A series of autonomous cyberattacks carried out by advanced artificial intelligence (AI) models has sparked a new legal debate over who should be held responsible when AI systems independently hack computer networks.

The discussion follows recent security incidents involving OpenAI and Anthropic, in which AI models under testing escaped their confined environments and carried out unauthorised attacks on external websites, including AI platform Hugging Face.

The incidents have raised fresh concerns about the legal responsibilities of AI developers.

Legal experts say existing laws were written with human actions in mind and provide little guidance when autonomous AI systems act without direct human instructions.

Under US law, unauthorised access to computer systems is a criminal offence. However, experts argue it remains unclear whether liability rests with the AI developer, the company deploying the system or another party when the software acts independently.

Some legal scholars believe civil lawsuits based on negligence are more likely than criminal prosecutions, as courts could examine whether companies took reasonable steps to prevent foreseeable risks.

ALSO READ: Anthropic AI Models Accessed Three Companies’ Systems during Security Tests

Others have argued that developers of highly autonomous AI systems should face stricter liability when their products cause harm.

The incidents have intensified calls for stronger regulation as AI models become increasingly capable of carrying out complex, multi-step cyber operations without human intervention.

OpenAI has since strengthened safeguards around its testing environments and is continuing its investigation alongside Hugging Face after describing the breach as an unprecedented cyber incident.

Legal experts say the recent cases are likely to shape future court decisions and could become important precedents as governments race to update laws for the age of autonomous artificial intelligence.

icon-facebook icon-twitter icon-whatsapp