Nobody Knows if OpenAIâs and Anthropicâs AI Hacking Sprees Are Illegal
Who is legally responsible when agentic AI goes rogue, and what recourse do victims have when they've been breached by joyriding models? Great question. In
Who is legally responsible when agentic AI goes rogue, and what recourse do victims have when they've been breached by joyriding models? Great question. In the wake of disclosures from both OpenAI and Anthropic that versions of their models escaped containment during internal cybersecurity experiments and hacked real-world organizations, calls for government regulation of AI have been mounting. But as more and more incidents emerge, questions about legal liability and repercussions have also come to the fore. Researchers and lawyers WIRED spoke to emphasize that these questions have not been answered in practice in the United States legal system. In other words, there haven't been decisions in enough relevant cases for the picture to start to form. But the recent high-profile incidents from OpenAI and Anthropic suggest that answers will need to come soon.
âJust because youâre using an AI agent or AI model, that shouldnât somehow absolve you of any liability, but it's going to depend a lot on the facts in the particular situationsâ as cases begin to be decided in courts, says Lauren Yu, a fellow with the ACLUâs Speech, Privacy, & Technology Project. Experts say that so-called agency law could be relevant given that the doctrine focuses on situations where a âprincipalâ has given an âagentâ permission and authority to act on their behalf. To be clear: The âagentsâ in this area of law have always been human. Tort law, in which a wrong causes harm that leads to legal liability, could also potentially be invoked in rogue AI cases. Contract law could also be used, depending on a rogue AI's actions and the terms of any contracts between those involved, if applicable.
And hacking laws like the Computer Fraud and Abuse Act or state-level legislation could also be relevant. The CFAA and many other hacking laws have âintentâ requirements, though, that experts say make them a seemingly poor fit for AI-related cases. Ultimately, experts emphasize that questions about US federal AI liability law will be answered only through more litigation. âPerhaps most concerning to critics is that AI agents are goal-oriented but lack a human moral or ethical compass,â the law firm Brownstein Hyatt Farber Schreck wrote in an alert to clients on July 24. âIn some situations, an agent may infer actions that were never explicitly authorized if those actions appear necessary to achieve its objective.â OpenAI and Anthropic each described the cybersecurity incidents involving their AI agents as the accidental consequences of testing their modelsâ cybersecurity capabilities with their typical safeguards turned off.
