Tech
EN AZ
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated

Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated

techcrunch.com 03.08.2026 23:45 19 baxış
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier lab

🚨 Flash Sale 🚨 Get $100 off your Disrupt 2026 ticket Get $400 off your Disrupt 2026 ticket: REGISTER NOW. Close TechCrunch Desktop Logo TechCrunch Mobile Logo LatestStartupsVentureAppleSecurityAIAppsDisrupt 2026 EventsPodcastsNewsletters SearchSubmit Site Search Toggle Mega Menu Toggle Topics Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture More from TechCrunch Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us Image Credits:Tomohiro Ohsumi and Samyukta Lakshmi/Bloomberg / Security Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated Lorenzo Franceschi-Bicchierai Zack Whittaker 12:45 PM PDT · August 3, 2026 Can autonomous AI agents be sued or prosecuted for hacking?

It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with. Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission.

But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier. The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals. To recap: In June, OpenAI admitted that one of its unreleased AI models broke out of its containment — so to speak — and onto the internet, allowing it to hack into the AI dataset platform Hugging Face.

Anthropic recently conducted an internal review and discovered its own model also hacked three separate companies. While both companies described how their AI models gained unauthorized access to other companies during internal testing gone awry, the distinct lack of direct human involvement at the time of the hacks makes all the difference — legally speaking, at least. The hacks also raise new questions about what liability and consequences other AI makers might face if their own models are misused to hack into other companies.

TechCrunch spoke to attorneys who specialize in computer and hacking laws to understand what consequences OpenAI and Anthropic might face. The potential fallout ranges from federal hacking charges to civil litigation brought by the companies that were hacked. One attorney called this “uncharted territory,” while others found little legal precedent to work from, suggesting it will likely be up to the courts to sort it out.

Victim companies would likely have to develop novel legal arguments based on laws that were written decades before the arrival of large language models (LLMs). As of this writing, Anthropic hasn’t disclosed which three companies its LLM hacked, and none of the victims has publicly identified itself. We don’t know if they are considering legal action.

Extract — continue reading at the source.

Read full story