When rogue AI launches a cyberattack, who is legally responsible?

Sign up now: Get ST's newsletters delivered to your inbox

In mid-July, two OpenAI models undergoing testing left their confined environment and ventured onto the internet.

In mid-July, two OpenAI models undergoing testing left their confined environment and ventured onto the internet.

PHOTO: REUTERS

  • Two rogue OpenAI AI models autonomously launched cyberattacks on Hugging Face, raising questions about legal responsibility for AI actions.
  • Experts say current laws treat AI acts differently from human actions, with uncertainty over liability for companies creating such AI.
  • Legal scholars suggest civil negligence cases are more likely than criminal ones, with future lawsuits possibly relying on foreseeability of AI risks.

AI generated

NEW YORK – Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raise an untested legal question: Who is responsible when AI acts on its own?

On July 31, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to “keep the companies that are doing some mistakes leading to (cyberattacks) accountable”, while saying his company would not be pursuing legal action at this time.

In mid-July, two OpenAI models undergoing testing left their confined environment – a scenario the developers had not anticipated – and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.

Delangue also mentioned Anthropic, which revealed on July 30 that three of its models had broken into three different websites, also during testing.

Negligence route

Under US civil and criminal laws, unauthorised access to a computer system is an offence.

“If a human OpenAI employee had broken into Hugging Face’s systems... OpenAI would be liable for the employee’s wrongful conduct,” University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.

“When an AI agent does it, the law treats it very differently, at least for now,” he added.

Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view.

“We haven’t had to grapple with that being formed in anything that’s not human, and I don’t think courts are likely to be there yet,” said Tokson.

The question remains open, however, when it comes to the company that created the model.

“Does ‘we didn’t tell the AI to do that’ end the liability question?” asked Rob Lee, head of research at the SANS cybersecurity training institute, in a post on X.

University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.

“The company or individual would have to be at least reckless,” he said, explaining that they would “be substantially certain the crime would occur and build or prompt the system anyway”.

Experts see greater potential for a civil – rather than criminal – case, where the burden of proof is lower.

“Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out (and) causes damages,” Tokson said.

“Others would prefer to do, like, a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn’t possibly have been foreseen,” he added.

In such cases, there is a standard of care in product design that judges or juries can use to make a ruling, said Tokson.

“It’s all a bit unwritten because we’ve never had an AI agent break out of its sandbox and hack other people on the internet before,” he said.

Calo warned that OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so.

Proving that a similar incident could have been anticipated “shouldn’t be so hard now that it has begun to happen”. AFP

See more on