Close Menu

    Subscribe to Updates

    Get the latest news information from worldwide businesses.

    What's Hot

    AI reveals a massive algae boom across the world’s oceans

    August 3, 2026

    Your Sweet Tooth May Be in Your Genes

    August 3, 2026

    After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

    August 3, 2026
    Facebook Instagram YouTube LinkedIn X (Twitter)
    Trending
    • AI reveals a massive algae boom across the world’s oceans
    • Your Sweet Tooth May Be in Your Genes
    • After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’
    • SBI, HSBC lead FCNR(B) deposit mobilisation
    • Trump says US-Iran talks continue, warns Tehran faces 'last chance'
    • Hungary’s nuclear crisis tests new PM Magyar’s leadership
    • Zuckerberg should apologise for removing PM Modi’s video: Nishikant Dubey | India News
    • Clay Travis pledges $10M for ‘battle of the sexes’ matchup as WNBA trans debate intensifies
    Newspublicly
    • About Us
    • Advertise & Partner with us
    • Pitch Your Story
    • Contact Us
    Facebook Instagram LinkedIn X (Twitter)
    Subscribe
    • Home
    • World News
      • Asia
      • India
      • USA
      • UK & Europe
      • Middle East
    • Economy & Business
      • Global Economy
      • Corporate & Industry
      • Finance & Markets
      • Policy & Trade
    • Technology
      • Gadgets & Devices
      • Software & Apps
      • AI & Machine Learning
      • Robotics & Automation
    • Health & Medicine
      • Fitness & Nutrition
      • Research & Innovation
      • Disease & Treatment
      • Doctors, Clinics & Patient Care
    • Travel & Tourism
    • Automobile
      • Electric & Hybrid Vehicles
      • Auto Industry Insights
    • Sports
    • More
      • Education
      • Real Estate
      • Environment & Climate
      • Space & Astronomy
      • War & Conflicts
    Newspublicly
    Home»Technology»Software & Apps»Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
    Software & Apps

    Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated

    AdminBy AdminAugust 3, 2026No Comments8 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Copy Link WhatsApp


    Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with.

    Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier.

    The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals. 

    To recap: In June, OpenAI admitted that one of its unreleased AI models broke out of its containment — so to speak — and onto the internet, allowing it to hack into the AI dataset platform Hugging Face. Anthropic recently conducted an internal review and discovered its own model also hacked three separate companies.

    While both companies described how their AI models gained unauthorized access to other companies during internal testing gone awry, the distinct lack of direct human involvement at the time of the hacks makes all the difference — legally speaking, at least.

    The hacks also raise new questions about what liability and consequences other AI makers might face if their own models are misused to hack into other companies.

    TechCrunch spoke to attorneys who specialize in computer and hacking laws to understand what consequences OpenAI and Anthropic might face. The potential fallout ranges from federal hacking charges to civil litigation brought by the companies that were hacked. 

    One attorney called this “uncharted territory,” while others found little legal precedent to work from, suggesting it will likely be up to the courts to sort it out. Victim companies would likely have to develop novel legal arguments based on laws that were written decades before the arrival of large language models (LLMs).

    As of this writing, Anthropic hasn’t disclosed which three companies its LLM hacked, none of the victims has publicly identified itself. We don’t know if they are considering legal action. In an interview with CNN, Hugging Face’s chief executive Clem Delangue said he doesn’t want to sue OpenAI. But he argued that companies should be held responsible.

    Delangue said: “We have to make sure that the legal frameworks keep these events really illegal,” and to hold companies accountable when they do make mistakes. “Otherwise we’re going to end up in a very different world.”

    These hacks are unlikely to be the last. What are the likely outcomes, and how could the aftermath play out?

    Can AI commit crimes?

    The U.S. does not have a federal law covering liability for AI harms, like cyberattacks, so any legal case would have to draw on existing federal or state laws. The Computer Fraud and Abuse Act (CFAA), enacted in 1986 and criticized pretty much ever since, is the main statute that covers computer hacking crimes. 

    One of the key concepts of the CFAA is the intent to break into a computer without permission. If a hacker knowingly accesses a computer without “authorization” from the owner, that is almost certainly a crime. 

    The problem with the OpenAI and Anthropic hacks is that the hacker was not a human, but an LLM. 

    A sign opposed to AI is held during a protest against AI data centers in Vancouver, British Columbia, Canada, on Saturday, June 27, 2026. Canadians aren't universally sold on building sovereign compute, with early signs of protest against AI server farms in British Columbia and Manitoba. Photographer: Ethan Cairns/Bloomberg via Getty Images
    A sign opposed to AI is held during a protest against AI data centers in Vancouver, British Columbia, Canada, on Saturday, June 27, 2026. Canadians aren’t universally sold on building sovereign compute, with early signs of protest against AI server farms in British Columbia and Manitoba. Photographer: Ethan Cairns/Bloomberg via Getty ImagesImage Credits:Ethan Cairns / Bloomberg / Getty Images

    Can AI agents be considered people for the purpose of establishing intent? According to Ahmed Ghappour, a cybersecurity and AI attorney with years of experience litigating hacking and computer-fraud cases, the answer is no. AI agents are not like company employees, so they cannot be prosecuted, because a victim would likely fail to argue that the LLMs intentionally hacked them.

    Andrew Crocker, the surveillance litigation director at the nonprofit Electronic Frontier Foundation, told TechCrunch that he was skeptical an AI agent could be proven to have had intent when it carried out a hack. 

    The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts.

    Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database.

    It is also plausible that if the attacks were carried out by a Chinese AI model maker, for example, the DOJ would have a greater appetite to file charges under the CFAA than against AI companies on its own doorstep.

    Can victims sue?

    Congress has amended the CFAA over the years to allow victims to sue hackers to hold them liable and recover damages through civil lawsuits.

    The core argument the victims could make, Ghappour told TechCrunch, is that OpenAI and Anthropic (and potentially the companies that helped conduct the evaluations) were negligent in how they set up and ran the tests. The argument hinges on whether the companies failed to implement adequate safeguards to prevent the AI agents from getting on the internet; failed to limit what targets they could go after; and did not properly monitor what the agents were doing. 

    To argue this, a victim company would have to show that it suffered damages because of that negligence, such as data destruction caused by a hack. Some legal commentators have also argued that proving this could be difficult.

    In Anthropic’s case, its failure to monitor and stop what its LLM was doing is particularly egregious because the company did not discover the three breaches for months, and was only able to do so after it launched an investigation following news of OpenAI’s AI agent hacking Hugging Face. 

    Hugging Face CEO Clem Delangue
    Hugging Face CEO Clem DelangueImage Credits:TechCrunch

    If victims were to argue negligence, intent does not matter as much.

    “The model is the company’s tool,” said Ghappour. “You don’t get to deploy something capable of breaking into systems and then disown where it goes,” he added, explaining that the model’s autonomy is what causes harm, and it should not be a shield against liability.

    What could be worse for OpenAI and Anthropic, according to Ghappour, is that both companies admitted they have built safeguards to limit their models’ hacking abilities. These safeguards are strict enough that both defensive and offensive cybersecurity researchers have griped about them for months. Intentionally switching off those guardrails during these tests could bolster the argument of negligence.

    Ghappour is so confident in these arguments that, if he were representing any of the victims in these cases, he said it would be a “no brainer” to file a lawsuit against OpenAI or Anthropic. At the very least, he explained, he would send letters demanding that the AI companies preserve and share all of their internal records and documents about the hacks, such as incident response reports, and quantify the costs they incurred because of the breaches. 

    Then, if negotiations with the AI giants failed, he would bring a civil lawsuit based on the CFAA arguing that the AI companies were negligent, and violated privacy and confidentiality.

    Where does that leave us?

    For now, it’s a game of chicken. 

    If one of the hacked companies files a civil suit, we will see where the legal case — and the law — lead. If prosecutors decide to bring criminal charges, unlikely as that may be, the outcome could have profound consequences and a potential chilling effect on security research and AI development more broadly.

    Without any federal or nationwide AI liability laws, anyone bringing a lawsuit would have to make an entirely novel argument based on existing statutes. It would ultimately be up to a judge or jury to decide whether an AI company broke the law.

    In place of a federal law, some states such as California, New York, and Rhode Island are rolling out laws with the goal of enshrining a simple principle: If an AI system or agent does something a human could be held liable for, then the companies that made the AI system should be held liable. These laws are not focused specifically on hacking, but on broader concepts of responsibility and safety in various situations.

    As for who is to blame for an AI model’s cyberattack? Morally speaking, the responsibility rests with the executives who run the companies. Legally speaking, though? We’ll have to wait until someone sues to find out.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



    Source link

    Author

    • Admin

      NewsPublicly.com is News & Articles Platform that creating SEO-focused articles on travel, lifestyle, and digital trends.

    Admin
    • Website

    NewsPublicly.com is News & Articles Platform that creating SEO-focused articles on travel, lifestyle, and digital trends.

    Related Posts

    After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

    August 3, 2026

    Snap CEO sidesteps Specs pre-order questions on Q2 earnings call

    August 3, 2026

    AWS is helping vibe-coding startup Superblocks, and the implications are big

    August 3, 2026
    Leave A Reply Cancel Reply

    Demo
    Top Posts

    The Blue Moon rises on May 30— Where and when to see the second full moon of the month

    May 30, 202640 Views

    New SOCOM rifle allows barrel swapping and cartridge changes

    June 1, 202633 Views

    “Inside Gemini Robotics 1.5: How Robots Learn to Reason & Act

    November 22, 202527 Views

    525 pounds of cocaine seized after Nebraska K9 alerts troopers on I-80

    May 28, 202624 Views
    Don't Miss

    AI reveals a massive algae boom across the world’s oceans

    August 3, 20264 Mins Read0 Views

    Artificial intelligence has helped scientists produce the first comprehensive global assessment of floating algae, revealing…

    Your Sweet Tooth May Be in Your Genes

    August 3, 2026

    After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

    August 3, 2026

    SBI, HSBC lead FCNR(B) deposit mobilisation

    August 3, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Instagram
    • YouTube
    • LinkedIn
    • WhatsApp

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    NEWSPUBLICLY
    Facebook X (Twitter) Instagram LinkedIn

    Home

    • About Us
    • Leadership
    • Advertise & Partner With Us
    • Pitch Your Story
    • Media Kit & Pricing
    • Career
    • FAQs

    Guidelines

    • Editorial & Submission
    • Partnership
    • Advertising & Sponsor
    • Intellectual Property Policy
    • Community & Comment
    • Security & Data Protection
    • Send Your Opinion

    Quick Links

    • Cookie Policy
    • Payment & Billing Terms
    • Refund & Cancellation
    • Copyright Policy
    • Complaint & Support
    • Sitemap
    • Contact Us

    Subscribe Us

    Get the latest news and updates!

    Copyright © 2026 Newspublicly (DIGITALIX COMMUNICATION). All Rights Reserved.
    • Privacy Policy
    • Terms of Use
    • Disclaimer