Who is legally liable after a cyberattack by rogue AI?

1 day ago 13
AI appsIn July 2026, two OpenAI models undergoing testing left their confined environment — a scenario the developers had not anticipated. Photo by Martin LELIEVRE /AFP

Article content

Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raise an untested legal question: who is responsible when AI acts on its own?

National Post

THIS CONTENT IS RESERVED FOR SUBSCRIBERS

Enjoy the latest local, national and international news.

  • Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.
  • Unlimited online access to National Post.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles including the New York Times Crossword.
  • Support local journalism.

SUBSCRIBE FOR MORE ARTICLES

Enjoy the latest local, national and international news.

  • Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.
  • Unlimited online access to National Post.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles including the New York Times Crossword.
  • Support local journalism.

REGISTER / SIGN IN TO UNLOCK MORE ARTICLES

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account.
  • Share your thoughts and join the conversation in the comments.
  • Enjoy additional articles per month.
  • Get email updates from your favourite authors.

THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account
  • Share your thoughts and join the conversation in the comments
  • Enjoy additional articles per month
  • Get email updates from your favourite authors

Sign In or Create an Account

or

Article content

On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to “keep the companies that are doing some mistakes leading to (cyberattacks) accountable,” while saying his company would not be pursuing legal action at this time.

Article content

Article content

Article content

In mid-July, two OpenAI models undergoing testing left their confined environment — a scenario the developers had not anticipated — and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.

Article content

By signing up you consent to receive the above newsletter from Postmedia Network Inc.

Article content

Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.

Article content

Negligence route

Article content

Under U.S. civil and criminal law, unauthorized access to a computer system is an offence.

Article content

“If a human OpenAI employee had broken into Hugging Face’s systems… OpenAI would be liable for the employee’s wrongful conduct,” University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.

Article content

Hugging Face CEO Clement Delangue said his company would not pursue legal action after falling victim to a cyberattack. (CHIP SOMODEVILLA/GETTY IMAGES NORTH AMERICA/AFP) Hugging Face CEO Clement Delangue said his company would not pursue legal action after falling victim to a cyberattack. (CHIP SOMODEVILLA/GETTY IMAGES NORTH AMERICA/AFP) Photo by CHIP SOMODEVILLA /GETTY IMAGES NORTH AMERICA/AFP

Article content

“When an AI agent does it, the law treats it very differently, at least for now,” he added.

Article content

Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying “we haven’t had to grapple with that being formed in anything that’s not human, and I don’t think courts are likely to be there yet.”

Article content

The question remains open, however, when it comes to the company that created the model.

Article content

Article content

“Does ‘we didn’t tell the AI to do that’ end the liability question?” asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.

Article content

Article content

University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.

Article content

“The company or individual would have to be at least reckless,” he said, explaining they would “be substantially certain the crime would occur and build or prompt the system anyway.”

Article content

Experts see greater potential for a civil — rather than criminal — case, where the burden of proof is lower.

Article content

“Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages,” Tokson explained.

Article content

“Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn’t possibly have been foreseen,” he added.

Article content

In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.

Article content

“It’s all a bit unwritten because we’ve never had an AI agent break out of its sandbox and hack other people on the internet before,” he said.

*** Disclaimer: This Article is auto-aggregated by a Rss Api Program and has not been created or edited by Bdtype.

(Note: This is an unedited and auto-generated story from Syndicated News Rss Api. News.bdtype.com Staff may not have modified or edited the content body.

Please visit the Source Website that deserves the credit and responsibility for creating this content.)

Watch Live | Source Article