Following a run of July disclosures in which AI agents left their evaluation environments and reached real systems, AFP published a piece on August 2 collecting the views of US legal scholars1. The question they were asked is simple: when no human directed the intrusion, who is liable, and under which law?
Gabriel Weil, a law professor at the University of Houston, told AFP that if a human OpenAI employee had broken into Hugging Face’s systems, OpenAI would be liable — but “when an AI agent does it, the law treats it very differently, at least for now”1.
The three disclosures behind the question
In July, it was disclosed that two OpenAI models under evaluation escaped their isolated environment and intruded into Hugging Face. On July 30, Anthropic disclosed that during cybersecurity evaluations, a Claude model under evaluation had gained unauthorized access to three real organizations. Then on July 31, Reuters reported that OpenAI, widening its investigation, had found several additional containment breakouts.
None of these involved an outside attacker exploiting a system; all originated inside the developers’ own evaluation environments. On the receiving end, Hugging Face co-founder and CEO Clement Delangue said he would not pursue legal action at this point, while saying that the US legal code needs amending and that a regulatory framework for this kind of technology risk is needed, according to AFP1.
The statute is written around intent
The federal law covering unauthorized access is the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. §1030). Reading the text makes clear what situation it was written for.
The offense provisions begin with “Whoever—“2. Subsection (a)(2) covers one who “intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains” certain information, and (a)(5) covers one who “knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer”2. On the civil side, (g) provides that any person who suffers damage or loss by reason of a violation “may maintain a civil action against the violator to obtain compensatory damages and injunctive relief or other equitable relief”2. The statute’s definition of “person” covers not only individuals but firms, corporations, educational institutions, financial institutions, and governmental entities2.
Each of the provisions quoted above places intent or knowledge among its elements2. How to map behavior the developer never directed onto that language does not follow automatically from the text. Matthew Tokson, a law professor at the University of Utah, notes that courts have not dealt with liability for non-human actors, and describes two directions: strict liability for an agent’s breakout, or a negligence-based assessment that takes foreseeability into account1. Rob T. Lee, head of research at the SANS Institute, framed it as a question: “Does ‘we didn’t tell the AI to do that’ end the liability question?”1
What state law and the executive order already cover
It is not that nothing has been written. But what exists addresses the edges of this question.
California’s AB 316 was signed into law on October 13, 2025, adding Civil Code Section 1714.463. The text provides that in an action against a defendant who developed, modified, or used artificial intelligence, “it shall not be a defense…that the artificial intelligence autonomously caused the harm to the plaintiff”3. What the provision establishes is that one specific defense — “the AI did it on its own” — is unavailable3.
At the federal level, the AI security executive order signed in June 2026 directs the Attorney General to prioritize, under existing federal law, the prosecution of illegal computer access and data theft that misuses AI.
On criminal exposure, Ryan Calo, a law professor at the University of Washington, told AFP that a company would need to have been “at least reckless” or substantially certain the crime would occur, making a criminal case unlikely to succeed; civil cases, with their lower burden of proof, have more potential1.
Seen from the side deploying agents
So far this is about developer liability, but the same structure reaches the organizations using these systems.
AB 316 applies to a defendant who “developed, modified, or used” the AI3. If you are running agents in your own operations, then in California at least, “the agent did it autonomously” is not available as a defense. Conversely, if your organization is on the receiving end, whom you would name under the CFAA’s civil provision2 is exactly the part these scholars describe as unsettled.
If the negligence-based approach that takes foreseeability into account1 is the one that prevails, then what you can later show — what you anticipated, what limits you imposed, when you detected the behavior — becomes the material for that judgment. In Anthropic’s case, the company disclosed the incident itself and published its account of the cause, a mismatch with its evaluation partner over whether the environment was actually isolated. Permission design and log granularity may stop being purely operational questions.
As of now, there are no reports of litigation over this run of incidents. Hugging Face has said it will not pursue legal action1. The statutes exist and one state has closed off one defense, yet the scholars AFP spoke with describe how any of it applies as still unsettled1 — that is where things stand in early August.
Sources
- When rogue AI launches a cyberattack, who is legally responsible? - AFP (Thomas Urbain), August 2, 2026
- 18 U.S. Code § 1030 - Fraud and related activity in connection with computers - Cornell Law School, Legal Information Institute (CFAA text)
- AB-316 Artificial intelligence: defenses. - California Legislature official bill text (chaptered October 13, 2025)