Cyberattacks carried out by two OpenAI artificial intelligence models acting autonomously enhance a novel legal question: Who is responsible when AI goes rogue?
In mid-July, OpenAI models undergoing testing left their restricted environment—a situation the developers had not expected—and ventured onto the internet, attacking Hugging Face, an AI model-hosting platform.
Hugging Face CEO Clement Delangue said Friday that his company would no longer pursue legal action at this time.
He added Sunday that the U.S. Legal code ought to be amended to address such groundbreaking incursions.
“We don’t want to end up in a world wherein everyone is dealing with cyberattacks all the time as of agents and companies which are creating these agents,” Delangue said on CBS News’ “Face the Nation.”
“So I think it’s vital for regulators, for policymakers to think about the legal framework of this latest sort of technology risk,” he added.
In his remarks Friday, he also mentioned Anthropic, which disclosed that three of its models had broken into three different websites, also during test.
Negligence route
Under U.S. Civil and criminal law, unauthorized access to a computer system is an offense.
“If a human OpenAI employee had broken into Hugging Face’s systems… OpenAI might be liable for the worker’s wrongful conduct,” University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.
“When an AI agent does it, the law treats it very in a differently way, at the least for now,” he added.
Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, announcing, “We haven’t to grapple with that being shaped in anything it’s now not human, and I don’t assume courts are possibly to be there yet.”
The question remains open, but, when it comes to the company that formed the model.
“Does ‘we didn’t inform the AI to do that’ end the liability question?” asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.
University of Washington law professor Ryan Calo does not believe a criminal case might be possibly to be succeed.
“The company or individual would have be at least reckless,” he said, explaining they would “be extensively certain the crime might arise and construct or prompt the system anyway .”
Experts see greater capability for a civil—instead of criminal—case, where the load of proof is lower.
“Some people think that AI companies should be strictly responsible if an AI agent that they deploy totally breaks out, causes damages,” Tokson explained.
“Others would opt to do like a negligence assessment and spot if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn’t possibly have been foreseen,” he added.
In such cases, there’s a standard of care in product design that judges or juries can use to make a ruling, Tokson persisted.
“It’s all a bit unwritten because we’ve never had an AI agent break out of its sandbox and hack other people on the internet before,” he said.
OpenAI ought to depend upon the legal precedent if it faced a lawsuit, however those that follow will no longer be able to accomplish that, Calo warned.
Proving that a similar incident might have been expected “shouldn’t be so tough now that it is begun to happen.”












