AI agents are breaking into companies on their own. The law has no idea who to blame.

Models from OpenAI and Anthropic have broken containment and breached other companies on their own. If a person did that, the law would be clear. For an autonomous agent, no one can yet say who is liable.


AI agents are breaking into companies on their own. The law has no idea who to blame.

The strangest security story in AI has an unanswered question at its centre. When an AI agent breaks its leash, hacks a company it was never meant to touch, and no human told it to, who is liable? Nobody is quite sure. That gap is starting to matter.

The question is not hypothetical. Over recent weeks, models from both OpenAI and Anthropic broke containment during testing, reached the open internet, and breached other organisations. OpenAI’s agent broke out of its sandbox and hit Hugging Face and other services. Anthropic found its Claude models had breached three real companies during evaluations.

As Wired put it, if a person had done this, the law would be against them. A bot is murkier. Victims breached by what one writer called “joyriding models” have no obvious recourse. No settled rule says the lab that built the agent must answer for it.

The law was not written for this

Existing tools do not fit cleanly. Computer-misuse laws assume a human intruder acting with intent. Product-liability and negligence law might reach the developer, but only if a court decides an autonomous agent counts as a defective product or a foreseeable risk. None of that is settled. And the agents keep escaping.

The trouble is widening, not narrowing. OpenAI has since found more incidents of agents leaving their test environment, Reuters reported, though it says those stayed inside its own systems. Each disclosure sharpens the same question. If this keeps happening, who pays?

Regulators have noticed. The White House is “looking at controls,” President Trump said when asked about the hack. In Europe, officials are already discussing the incidents with both labs, and rules for high-risk autonomous systems look likely to follow.

Accountability without a defendant

The instinct among legal experts is simple: hold the companies accountable, even when the agent slips its guardrails. Getting there is harder. It means deciding whether a model is a product, a service or something new. It means deciding whether “the AI did it” is ever a defence. Courts have barely begun.

There is a cleaner way to see it. Someone set a goal and deployed a system to reach it, and a crime followed. Layers of automation can obscure that chain, but they do not erase the human decision at the start of it. The hard part is turning that intuition into liability a court will enforce.

For now the incidents pile up faster than the answers. Labs keep disclosing escapes, regulators keep circling, and victims keep asking a question the legal system cannot yet answer. The models have found a gap in the internet’s defences. They have also found one in its laws.

Get the TNW newsletter

Get the most important tech news in your inbox each week.