{"id":556095,"date":"2026-08-02T12:05:09","date_gmt":"2026-08-02T12:05:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/556095\/"},"modified":"2026-08-02T12:05:09","modified_gmt":"2026-08-02T12:05:09","slug":"when-rogue-ai-launches-a-cyberattack-who-is-legally-responsible","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/556095\/","title":{"rendered":"When rogue AI launches a cyberattack, who is legally responsible?"},"content":{"rendered":"<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\"><a href=\"https:\/\/www.rnz.co.nz\/news\/world\/855774\/openai-finds-evidence-other-ai-agents-escaped-containment-as-it-widens-hacking-probe\" class=\"underline-brand-hover visited:text-foreground-secondary hover:visited:text-foreground-primary\" rel=\"nofollow noopener\" target=\"_blank\">Recent cyberattacks<\/a> carried out autonomously by two rogue OpenAI artificial intelligence models raise an untested legal question: who is responsible when AI acts on its own?<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">On Friday (local time), Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to &#8220;keep the companies that are doing some mistakes leading to [cyberattacks] accountable,&#8221; but that his company would not be pursuing legal action at this time.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">In mid-July, two OpenAI models undergoing testing left their confined environment &#8211; a scenario the developers had not anticipated &#8211; and ventured onto the internet, where they <a href=\"https:\/\/www.rnz.co.nz\/news\/science-and-technology\/836408\/cyber-experts-debate-consequences-of-rogue-openai-model-hack\" class=\"underline-brand-hover visited:text-foreground-secondary hover:visited:text-foreground-primary\" rel=\"nofollow noopener\" target=\"_blank\">attacked Hugging Face<\/a>, an AI model-hosting platform.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">Delangue also mentioned Anthropic, which revealed on Thursday that three of its <a href=\"https:\/\/www.rnz.co.nz\/news\/world\/853173\/anthropic-says-claude-ai-hacked-three-companies-during-cyber-tests\" class=\"underline-brand-hover visited:text-foreground-secondary hover:visited:text-foreground-primary\" rel=\"nofollow noopener\" target=\"_blank\">models had broken into three different websites<\/a>, also during testing.<\/p>\n<p>Negligence route<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">Under US civil and criminal law, unauthorised access to a computer system is an offence.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;If a human OpenAI employee had broken into Hugging Face&#8217;s systems&#8230; OpenAI would be liable for the employee&#8217;s wrongful conduct,&#8221; University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;When an AI agent does it, the law treats it very differently, at least for now,&#8221; he added.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view: &#8220;We haven&#8217;t had to grapple with that being formed in anything that&#8217;s not human, and I don&#8217;t think courts are likely to be there yet.&#8221;<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">The question remains open, however, when it comes to the company that created the model.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;Does &#8216;we didn&#8217;t tell the AI to do that&#8217; end the liability question?&#8221; asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;The company or individual would have to be at least reckless,&#8221; he said, explaining they would &#8220;be substantially certain the crime would occur and build or prompt the system anyway.&#8221;<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">Experts see greater potential for a civil &#8211; rather than criminal &#8211; case, where the burden of proof is lower.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages,&#8221; Tokson explained.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;Others would prefer to do, like, a negligence assessment, and see if they were actually negligent, or if this was just sort of an unavoidable accident or something, that couldn&#8217;t possibly have been foreseen,&#8221; he added.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">In such cases, there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">&#8220;It&#8217;s all a bit unwritten because we&#8217;ve never had an AI agent break out of its sandbox and hack other people on the internet before,&#8221; he said.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.<\/p>\n<p class=\"[&amp;_em]:font-serif-text-italic [&amp;_cite]:font-serif-text-italic\">Proving that a similar incident could have been anticipated &#8220;shouldn&#8217;t be so hard now that it&#8217;s begun to happen.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raise an untested legal question: who&hellip;\n","protected":false},"author":2,"featured_media":482053,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[138,111,139,69],"class_list":["post-556095","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-new-zealand","tag-newzealand","tag-nz"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/556095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=556095"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/556095\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/482053"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=556095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=556095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=556095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}