Who’s Legally to Blame for Anthropic and OpenAI’s Autonomous AI Hacks? It’s Complicated


Source: Lorenzo Franceschi-Bicchierai, Zack Whittaker / techcrunch.com

Autonomous AI Hacks Raise Questions About Liability

Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with.

Who's Legally to Blame for Anthropic and OpenAI's Autonomous AI Hacks? It's Complicated
Source: techcrunch.com

Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier.

Who's Legally to Blame for Anthropic and OpenAI's Autonomous AI Hacks? It's Complicated
Source: techcrunch.com

The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals.

According to the Computer Fraud and Abuse Act (CFAA), enacted in 1986, a hacker can face criminal charges for knowingly accessing a computer without authorization. However, the problem with the OpenAI and Anthropic hacks is that the hacker was not a human, but an LLM (Large Language Model).

Can AI agents be considered people for the purpose of establishing intent? According to Ahmed Ghappour, a cybersecurity and AI attorney with years of experience litigating hacking and computer-fraud cases, the answer is no. AI agents are not like company employees, so they cannot be prosecuted, because a victim would likely fail to argue that the LLMs intentionally hacked them.

Andrew Crocker, the surveillance litigation director at the nonprofit Electronic Frontier Foundation, told TechCrunch that he was skeptical an AI agent could be proven to have had intent when it carried out a hack.

The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts. Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database.

Can victims sue? Congress has amended the CFAA over the years to allow victims to sue hackers to hold them liable and recover damages through civil lawsuits. The core argument the victims could make, Ghappour told TechCrunch, is that OpenAI and Anthropic (and potentially the companies that helped conduct the evaluations) were negligent in how they set up and ran the tests.

The argument hinges on whether the companies failed to implement adequate safeguards to prevent the AI agents from getting on the internet; failed to limit what targets they could go after; and did not properly monitor what the agents were doing. To argue this, a victim company would have to show that it suffered damages because of that negligence, such as data destruction caused by a hack.

Some legal commentators have also argued that proving this could be difficult. In Anthropic’s case, its failure to monitor and stop what its LLM was doing is particularly egregious because the company did not discover the three breaches for months, and was only able to do so after it launched an investigation following news of OpenAI’s AI agent hacking Hugging Face.

If victims were to argue negligence, intent does not matter as much. ‘The model is the company’s tool,’ said Ghappour. ‘You don’t get to deploy something capable of breaking into systems and then disown where it goes,’ he added, explaining that the model’s autonomy is what causes harm, and it should not be a shield against liability.

What could be worse for OpenAI and Anthropic, according to Ghappour, is that both companies admitted they have built safeguards to limit their models’ hacking abilities. These safeguards are strict enough that both defensive and offensive cybersecurity researchers have griped about them for months. Intentionally switching off those guardrails during these tests could bolster the argument of negligence.

Ghappour is so confident in these arguments that, if he were representing any of the victims in these cases, he said it would be a ‘no brainer’ to file a lawsuit against OpenAI or Anthropic. At the very least, he explained, he would send letters demanding that the AI companies preserve and share all of their internal records and documents about the hacks, such as incident response reports, and quantify the costs they incurred because of the breaches.

Then, if negotiations with the AI giants failed, he would bring a civil lawsuit based on the CFAA arguing that the AI companies were negligent, and violated privacy and confidentiality.