Comment Loader Save StorySave this story
Comment Loader Save StorySave this story
Who is legally responsible when agentic AI goes rogue, and what recourse do victims have when they've been breached by joyriding models? Great question.
In the wake of disclosures from both OpenAI and Anthropic that versions of their models escaped containment during internal cybersecurity experiments and hacked real-world organizations, calls for government regulation of AI have been mounting. But as more and more incidents emerge, questions about legal liability and repercussions have also come to the fore.
Researchers and lawyers WIRED spoke to emphasize that these questions have not been answered in practice in the United States legal system. In other words, there haven't been decisions in enough relevant cases for the picture to start to form. But the recent high-profile incidents from OpenAI and Anthropic suggest that answers will need to come soon.
“Just because you’re using an AI agent or AI model, that shouldn’t somehow absolve you of any liability, but it's going to depend a lot on the facts in the particular situations” as cases begin to be decided in courts, says Lauren Yu, a fellow with the ACLU’s Speech, Privacy, & Technology Project.
Experts say that so-called agency law could be relevant given that the doctrine focuses on situations where a “principal” has given an “agent” permission and authority to act on their behalf. To be clear: The “agents” in this area of law have always been human.
Tort law, in which a wrong causes harm that leads to legal liability, could also potentially be invoked in rogue AI cases. Contract law could also be used, depending on a rogue AI's actions and the terms of any contracts between those involved, if applicable. And hacking laws like the Computer Fraud and Abuse Act or state-level legislation could also be relevant. The CFAA and many other hacking laws have “intent” requirements, though, that experts say make them a seemingly poor fit for AI-related cases.
Ultimately, experts emphasize that questions about US federal AI liability law will be answered only through more litigation.
“Perhaps most concerning to critics is that AI agents are goal-oriented but lack a human moral or ethical compass,” the law firm Brownstein Hyatt Farber Schreck wrote in an alert to clients on July 24. “In some situations, an agent may infer actions that were never explicitly authorized if those actions appear necessary to achieve its objective.”
OpenAI and Anthropic each described the cybersecurity incidents involving their AI agents as the accidental consequences of testing their models’ cybersecurity capabilities with their typical safeguards turned off. Both companies declined WIRED’s request to comment for this story.
In the meantime, the hits keep on coming. Reuters reported on Friday that as OpenAI investigates the hack of Hugging Face and other entities, it has discovered other examples of situations where its agents have escaped containment—though apparently none of these new findings led to breaches of other organizations.
Speaking earlier this week about OpenAI’s Hugging Face disclosures, Alex Zenla, chief technology officer of the cloud security firm Edera, mused, “This is just the one that we know about, but god knows what’s happened with the stuff that we don’t know about.”
Most Popular
Digital Culture
Don’t Get Too Attached to Jimothy
By Miles Klee
Artificial Intelligence
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
By Louise Matsakis
Culture
Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books
By Miles Klee
Security News
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
By Kim Zetter
Comments
Join the discussion
Comments
You Might Also Like
-
In your inbox: This is not your average politics newsletter
-
WiFi-8 is coming—here’s everything you need to know
-
Big Story: Young runners are becoming freakishly fast
-
The new reality of urban surveillance
-
Take our survey: Do you work in tech? We want to hear from you
Lily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate, and was the staff writer for Future Tense, a publication and partnership between Slate, the New America Foundation, and Arizona State University. Her work ... Read More
Senior Writer
Topics artificial intelligence security cybersecurity machine learning hacking hacks OpenAI Anthropic
Don’t Get Too Attached to Jimothy
Urban wildlife biologists say the stumpy raccoon seems to have adapted well to his environment and spinal condition—but his internet fame presents a new threat.
Miles Klee
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during third-party evaluations.
Louise Matsakis
Boomers Can’t Stop Gifting Their Grandkids AI-Generated Slop Books
Parents are getting fed up with garbled bedtime stories that feature characters based on actual photos of their children.
Miles Klee
A Teen Reporter Searched for His Community in the Epstein Files. Adults Freaked Out
An Instagram post turned one California student newspaper into a free-speech flash point. The students say they were just doing their homework.
Ara Rosenthal
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
Kim Zetter
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
Andy Greenberg
NASA’s New 3D Model Shows the Earth Is a Lumpy Mess
We like to think of our home as a nice, smooth sphere. But mapping the Earth’s gravitational field provides a different view of the planet.
Javier Carbajal
Can Republicans Actually Send Anthony Fauci to Jail?
MAGA is loudly calling for the former White House chief medical adviser to end up in prison. WIRED asked legal experts to weigh in on whether that’s even possible.
David Gilbert
OpenAI’s Hacking Debacle Comes Down to Human Error
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
Lily Hay Newman
More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’
Novelists, journalists, and power LinkedIn posters are embracing first-person narratives and idiosyncrasies to avoid being mistaken for chat bots.
Emma Madden
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
Scammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links.
Matt Burgess
Google’s Gemini Can Now Stomp Around as a Humanoid Robot
The latest version of Google DeepMind's AI model includes a significant jump into “physical AGI.” But plopping AI into the real world comes with risks.
Will Knight
Read Original at wired.com →

