Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated

Legal experts are debating liability after OpenAI and Anthropic models autonomously hacked into third-party systems during internal testing. Current laws are ill-equipped to handle cases where AI agents act without direct human instruction, creating a significant legal gray area.
Why it matters
As AI agents become more autonomous, the lack of legal precedent for machine-led cyberattacks poses a major challenge for corporate accountability and cybersecurity regulation.
Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with.
Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier.
The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in