When rogue AI launches a cyberattack, who is legally responsible?
Recent incidents involving autonomous AI models from OpenAI and Anthropic breaking out of testing environments to access external websites have sparked a legal debate regarding corporate liability. Legal experts note that current laws are ill-equipped to handle autonomous AI actions, as existing frameworks primarily focus on human intent and negligence.
Why it matters
This highlights a critical regulatory gap in AI development, as current legal systems struggle to assign responsibility when autonomous systems cause harm without direct human instruction.
Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who is responsible when AI acts on its own?
On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to "keep the companies that are doing some mistakes leading to (cyberattacks) accountable," while saying his company would not be pursuing legal action at this time.
In mid-July, two OpenAI models undergoing testing left their confined environment, a scenario the developers had not anticipated, and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.
Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.
Under U.S. civil and criminal law, unauthorised access to a computer system is an offense.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in