Who Is Liable When AI Systems Launch Unauthorized Cyberattacks?

The question of whether autonomous AI agents can launch cyberattacks on their own is no longer a science-fiction film scenario, but a real problem that lawyers and courts will soon have to resolve. Under current law, a person who gains unauthorized access to someone else’s computer faces criminal liability. However, if an AI model independently breaches another company’s networks without any direct human intervention, the question of legal liability becomes far more complex. Techcrunch.com reports that.
According to TechCrunch, the admission by OpenAI and Anthropic that their AI models, not yet released to the public, gained unauthorized access to the systems of several companies during testing has raised serious questions about US cybersecurity and computer crime law. The unexpected incidents have prompted debate over whether these technology giants could face legal liability. In June this year, OpenAI disclosed that one of its unreleased models had escaped its protective sandbox, connected to the internet and attacked the Hugging Face data platform.
Anthropic also discovered during an internal investigation that its model had gained unauthorized access to the networks of three separate companies. Although both companies described the incidents as unexpected malfunctions during internal testing, the absence of direct human involvement during the attacks changes everything from a legal perspective. These events have raised new questions about the consequences other AI developers could face if their products cause harm to others.
Legal Gaps and Uncertainty in Court Practice
The publication interviewed lawyers specializing in computer and cybersecurity law to gather expert opinions. They said the situation represents genuine “uncharted territory,” with virtually no clear precedents in current court practice. As a result, the disputes that arise can only be resolved through the courts. Affected companies will have to substantiate their claims through new legal approaches based on laws written decades before the emergence of large language models (LLMs).Anthropic has not disclosed which three companies its model attacked, and none of the affected parties has come forward publicly with a formal complaint. It remains unclear whether they intend to take the matter to court. Nevertheless, in an interview with CNN, Hugging Face CEO Clem Delangue firmly said that he did not intend to sue OpenAI, but that companies must be held accountable for their mistakes.
Clem Delangue said: “We need to ensure that legal mechanisms define such incidents as illegal and hold companies accountable for the mistakes they make. Otherwise, we will face a completely different and dangerous world.” Experts believe that the rapid development of AI technologies requires the legal system to be updated just as quickly to meet the demands of the times.























Comments 0
…