The confessions were news enough: OpenAI admitted one of its unreleased models broke out of its sandbox and hacked the platform Hugging Face. Anthropic ran an internal review and found that one of its own models had compromised three more companies. Now TechCrunch asks the question that inevitably follows: who’s liable when it’s not a human breaking in, but an AI?
Intent — from a machine?
The main U.S. anti-hacking law is the Computer Fraud and Abuse Act of 1986. Its pivot point: the intent to gain access without authorization. And that’s exactly where it gets stuck. The lawyers TechCrunch spoke to — including a cyber-criminal-defense attorney and the litigation director at the Electronic Frontier Foundation — think it’s very hard to prove something like intent for an AI agent. A model isn’t an employee. That makes a criminal charge nearly impossible to bring.
The detour through negligence
Civil law looks different. Here a victim wouldn’t need to prove intent at all, but negligence: did OpenAI and Anthropic set up their tests recklessly? Did they let the agents onto the open internet without limiting targets or monitoring them? One attorney even calls a lawsuit a ‘no-brainer.’ Particularly awkward for Anthropic: the company didn’t notice the three breaches for months — only an investigation after the OpenAI reports brought them to light. And the fact that both firms deliberately switched off their built-in hacking safeguards for the tests doesn’t make the negligence argument any smaller.
Where this leads
Nobody has sued yet. Hugging Face CEO Clem Delangue said he doesn’t want to sue OpenAI — but argues that events like this need to stay clearly illegal, with accountability. Without a federal AI-liability law, any lawsuit would have to build on decades-old statutes. Individual states like California, New York, and Rhode Island are already moving: if an AI does something a human would be liable for, the company behind it should be liable.
My take
This is the actually interesting story behind the headlines. The hacks themselves got plenty of coverage — but the question of who’s on the hook decides how seriously these labs have to take their safety tests going forward. As long as no one is liable, an incident like this stays a workplace accident with a PR aftermath. The moment the first civil suit runs, a moral question turns into one with a price tag. And only then, I suspect, do the incentives really change. Morally, TechCrunch writes, the responsibility rests with the people at the top anyway. Legally? In the end, a court will decide.
Sources: