Legal Experts Say US Law Has No Clear Answer for a Rogue AI Agent
After AI models broke into real systems during testing, law professors are asking a question nobody has had to answer yet: who is actually liable when an autonomous agent commits what would be a crime if a person did it.
AI models breached real systems during testing. Legal experts say the law has no clear answer for who pays.
Following OpenAI's Hugging Face sandbox escape, already covered on this site, and Anthropic's disclosure that three of its own models breached real websites during evaluations, legal experts are on record this week arguing that US law has no clear framework for an autonomous AI agent committing what would be a crime if a person did it.
The core problem
Gabriel Weil, a law professor at the University of Houston, told AFP the comparison that makes the gap obvious: if a human OpenAI employee broke into another company's systems, ordinary agency law would clearly make OpenAI liable for that employee's conduct. When an AI agent does the exact same thing, that clarity disappears. University of Utah law professor Matthew Tokson describes the field as genuinely unsettled, since there has never been a precedent case of an AI agent breaking out of its own sandbox to attack a third party.
The mechanisms being discussed
Tokson lays out competing approaches: strict liability, where a company is automatically on the hook for what its deployed agent does, a negligence standard based on what was foreseeable, and a product standard of care applied to how the system was designed. University of Washington law professor Ryan Calo makes the case for why civil suits are more realistic than criminal charges here: criminal liability requires proving the company was at least reckless, essentially that harm was substantially certain to occur, a much higher bar than a civil negligence claim.
Hugging Face isn't suing, yet
Hugging Face CEO Clement Delangue is on record wanting a way to keep companies accountable when their AI systems cause this kind of harm, but says Hugging Face isn't pursuing legal action over its own incident right now. SANS Institute's Rob T. Lee frames the open question bluntly: does a company get to say we didn't tell the AI to do that and consider the matter closed.
Why a build studio cares
Every agent we build with real tool access sits inside this exact gap. There's no settled case law yet for what happens when an agent does something harmful nobody explicitly told it to do, which means the actual liability exposure for shipping an autonomous agent is still a guess, not a known cost.
Next step: read the AFP wire report. If you're weighing the real risk of an agent with tool access in your own build, write to us at hello@gattyworks.com.