RSS Amplifier

Fairly AI · Aug 9, 2026

Who Is Accountable When AI Hacks?

0
Sign in to vote or save

Wei Chen · Fairly AI

Disclaimer: This blog reflects my personal opinion and does not constitute legal advice.

On August 3, fifteen state attorneys general sent a letter to Sam Altman, CEO of OpenAI. The letter demanded that OpenAI “preserve all potentially relevant documents, data, and information” related to the July security incident. It also asked that “OpenAI immediately cease and desist from all “internal evaluation[s that] prompt[] [OpenAI] models to pursue advanced exploitation using complex attack paths” and “ensure that no OpenAI personnel face any adverse action for engaging in any protected whistleblowing activity or for reporting any unlawful or harmful activities by OpenAI.” “A failure to take immediate action to preserve such materials”, the letter continues, “could result in spoliation sanctions if litigation were to ensue.”

Using legal terms, the letter does three things:

  1. It triggers a litigation hold — an obligation on OpenAI to stop routine document deletion and preserve everything that might be relevant to a potential future lawsuit.

  2. It demands a preliminary injunction — OpenAI needs to stop the evaluation until it shows that “it can conduct such activities in a controlled and responsible way.”

  3. It imposes an obligation of non-retaliation against whistleblowers.

Upon seeing this letter, I breathed a sigh of relief: the rule of law still has a voice.

Let’s refresh our memory on what happened.

On July 21, OpenAI admitted that it put a few AI models under cybersecurity testing with “reduced cyber refusals”. The agent using these models found a previously unknown vulnerability in third-party software, escaped its isolated environment, and hacked into another company, Hugging Face. On August 6, OpenAI researchers disclosed that the July incident was a breach traced back to May 7, when an agent compromised OpenAI’s own infrastructure before reaching Hugging Face’s servers two months later without detection.

On July 30, Anthropic announced that they had also been conducting similar tests and their AI agents using Claude had gained unauthorized access to the production environment of three different organizations without detection.

At the Berkeley AI summit last weekend, AI Researcher, Andrew Ng, pointed out the absurdity of the bragging match between the two leading AI labs on which model is more dangerous. When I hosted a webinar on the legal analysis of a hypothetical lawsuit of Hugging Face v. OpenAI, a participant asked me if there was any law against unauthorized hacking. When TechCrunch put this question to attorneys who specialize in computer crime, the answers were largely along the lines of “expressed doubts” or “uncharted territory”.

I am not experienced or brave enough to predict whether OpenAI and/or Anthropic will be sued or held liable, but suffice it to say, if a group of human employees at OpenAI or Anthropic hacked into Hugging Face or the three organizations to ace a test, both the employees and their employers would be held liable regardless of how capable or uncontrollable those employees were.

CFAA and Criminal Liability

Under the U.S. Computer Fraud and Abuse Act of 1986, as amended, “whoever intentionally accessed a computer without authorization or exceeding authorized access, and thereby obtains … information from any protected computer” faces criminal fine and/or imprisonment.

However, when AI was the one that initiated the unauthorized access, it may be difficult to hold OpenAI or Anthropic liable especially given that the law specifies that “no action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware.”

Agency Law & Vicarious Liability

For centuries, agency law has held companies liable for the acts of their human agents under the doctrine of vicarious liability. What happens if the “agents” are AI and not human?

On July 7, 2026, the UK Jurisdiction Taskforce published its final Legal Statement on Liability for AI Harms, a comprehensive analysis of how English private law would allocate responsibility when AI causes harm. Its central conclusion is that existing English law is generally capable of handling AI harms without a new AI-specific regime. After all, the law has absorbed disruptive technologies for hundreds of years by incrementally extending old principles.

  • The statement mirrors what the attorneys told TechCrunch: unlike a human or a corporate entity, “AI is not a legal person” and therefore “cannot be held liable in its own right.”

  • However, “an employer could – and generally would – be held vicariously liable for physical or economic harm caused by negligent use of AI by an employee” especially if “the employee was acting within the course of their employment”.

    • An example would be a hit-and-run case where an employee drove a company-provided semi-autonomous truck.

  • “Another circumstance in which [an employee]... may be liable for AI harm caused by another is where [the employee]… has a non-delegable duty to protect against that harm.”

    • An example would be when a hospital uses an AI diagnostic tool in patient care or a lawyer uses an AI chatbot to draft legal brief, a defect in the AI tool does not shield the doctor or the lawyer from malpractice because the AI tool is an integral part of the services that the hospital or law firm has assumed responsibility to provide. That duty is non-delegable.

California’s AB 316, effective January 1, 2026, clarified that: “in an action against a defendant who developed, modified, or used artificial intelligence that is alleged to have caused a harm to the plaintiff, it shall not be a defense, and the defendant may not assert, that the artificial intelligence autonomously caused the harm to the plaintiff.”

In short, the “AI did it” is not a sufficient defense by itself.

However, to hold employers accountable for their employees’ use of AI, we need to establish fault: (1) negligence, including employee’s negligence or a breach of non-delegable duty, or (2) the intent to harm, in each case by a legal person. This could be a high bar given the complex nature of AI. A trial to determine negligence could easily cost millions of dollars, involving tens of thousands of documents and tens or even hundreds of expert testimonies.

If a lawsuit were filed against OpenAI or Anthropic, whether their employees were negligent in giving powerful models a task to exploit vulnerabilities would depend on whether any harm was foreseeable. After July 9, the answer to foreseeability is clear. Even without the injunction request from the attorneys general, a responsible organization would pause such evaluations to avoid vicarious liability.

Product Liability Law and Strict Liability

One may argue that the most powerful AI models are so sophisticated that no employer should be considered at fault. That brings us to the one legal theory that does not require fault: product liability.

Product liability law holds the manufacturer of a product strictly liable for death, personal injury or damage to private property caused by a defective product. Strict liability does not require proof of fault, but it does require the plaintiff to prove that the product is defective.

But is AI a “product” under product liability law? Under the Restatement (Third) of Torts, a set of principles adopted by about 20% of the U.S. states, a product is defined as “tangible personal property distributed commercially for use or consumption”. The UK Consumer Protection Act 1987 takes a similar view.

Suffice to say, if AI is embedded in a physical thing used by a consumer, strict liability would follow under most laws globally. However, laws differ on whether an AI chatbot, agentic application, or open weight model alone would qualify as a “product”.

  • In the U.S., strict liability is decided by state courts. The Indiana Law Journal conducted a 50-state survey and found “courts diverging on whether software qualifies as a product, particularly in cases involving embedded or cloud-based solutions like software-as-a-service.” This inconsistency was demonstrated by one court in California holding the Uber app not to be a “product”, while another court in Florida held the Lyft app to be a “product”.

  • The UK Legal Statement took a more restrictive view, noting that “[g]iven that many AI applications – including many embedded AI applications – are in a commercial context, this removes a substantial number of potential claims from the ambit of the CPA 1987”, the UK consumer protection law.

  • The EU Product Liability Directive (2024/2853), to be transposed by member states into national laws by December 9, 2026, is heading in a different direction. It defines product as “all movables, … includes electricity, digital manufacturing files, raw materials and software”. In its non-binding recitals, the phrase “AI system” appeared six times, implying that certain AI systems would qualify as products. Free open-source software not integrated into a manufacturer’s product, on the other hand, is specifically excluded.

Once an AI system is deemed a “product”, the plaintiff would need to prove that the product is defective.

  • The UK Legal Statement notes that this might be as tall of an order as proving negligence: “where the product is a highly technical one (whether that is AI or otherwise), the enquiry process to assess ‘negligence’ and to assess ‘defect’ is likely to overlap substantially in practice.”

  • The EU Product Liability Directive (2024/2853), on the other hand, significantly eases the burden of proof by the plaintiff:

    • Once the plaintiff presents “facts and evidence sufficient to support the plausibility of the claim for compensation…, the defendant is required to disclose relevant evidence that is at the defendant’s disposal”.

    • The defectiveness of the product shall be presumed if the defendant fails to disclose such evidence, or if the plaintiff demonstrates that the product does not comply with mandatory product safety requirements.

Applying these principles to the OpenAI or Anthropic’s incidents, an unreleased model that escaped during internal testing was never placed on any market or distributed commercially for use or consumption. As a result, product liability likely won’t apply to these particular incidents. However, if a company decides to integrate these models into a physical product for sale or distribution, strict liability might apply.

Under the Restatement (Third) of Torts, any person injured by a defective product could directly sue the manufacturer and members of the chain of distribution. These members could include distributors or resellers of products that embed the defective AI model.

Similarly, the EU Product Liability Directive holds “economic operators” liable alongside the manufacturers. Economic operators could include an importer, distributor, or a reseller; a legal person that substantially modifies a product outside the manufacturer’s control is treated as a manufacturer.

The rapid development of frontier AI models has outpaced legal statutes, but centuries of common law are already adapting to fill the void. Here are a few takeaways:

  • The “AI did it” defense is invalid: Statutes like California’s AB 316 and established agency principles clarify that companies cannot hide behind the autonomy of their models. If an employee negligently deploys an AI agent or breaches a non-delegable duty, the employer is vicariously liable.

  • Foreseeability is no longer uncertain: Proving negligence requires proving that the harm was foreseeable. Following the highly publicized incidents involving OpenAI and Anthropic, the risk of AI agents conducting unauthorized acts has become an established, documented fact. Continuing such evaluations without adequate, verifiable safeguards carries significant legal risk.

  • AI is not immune from strict liability: The U.S. remains a patchwork of conflicting state court rulings on whether software qualifies as a “product” subject to strict liability. However, the EU is aggressively expanding strict liability to include digital files and software while simultaneously lowering the plaintiff’s burden of proof.

  • Providers, distributors and resellers can be liable: Once an AI model is embedded into a commercial product, liability extends down the entire commercial chain. Distributors, resellers, and economic operators may find themselves the targets of lawsuits if a defective product causes personal injury, death or damage to private property.

Ultimately, while the technology is unprecedented, the legal mechanisms to assign liability, whether through vicarious liability or strict product liability, is already there. The next few months will be interesting to watch, and I am delighted to see that there is no immunity for AI under the rule of law.

_______________________________

For more practical tips on AI governance and innovation, check out GenAI for the Legal Profession: Power User Edition, AI Strategy for Legal Leaders, and my Fairly AI blogs.

No posts

Read the original on weichen221.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.