Who's legally to blame for Anthropic and OpenAI's autonomous AI hacks?

mikelgan1 pts1 comments

Who's legally to blame for Anthropic and OpenAI's autonomous AI hacks? It's complicated | TechCrunch

SearchSubmit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Crunchboard

Contact Us

Image Credits: Tomohiro Ohsumi and Samyukta Lakshmi/Bloomberg / Getty Images

Security

Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated

Lorenzo Franceschi-Bicchierai

Zack Whittaker

12:45 PM PDT · August 3, 2026

Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with.

Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent autonomously hacks into a company’s computers, determining who is liable is much murkier.

The surprise admissions by OpenAI and Anthropic that their unreleased AI models autonomously hacked into several companies have upended our understanding of America’s computer hacking laws, prompting discussions over whether the companies could face legal reprisals.

To recap: In June, OpenAI admitted that one of its unreleased AI models broke out of its containment — so to speak — and onto the internet, allowing it to hack into the AI dataset platform Hugging Face. Anthropic recently conducted an internal review and discovered its own model also hacked three separate companies.

While both companies described how their AI models gained unauthorized access to other companies during internal testing gone awry, the distinct lack of direct human involvement at the time of the hacks makes all the difference — legally speaking, at least.

The hacks also raise new questions about what liability and consequences other AI makers might face if their own models are misused to hack into other companies.

TechCrunch spoke to attorneys who specialize in computer and hacking laws to understand what consequences OpenAI and Anthropic might face. The potential fallout ranges from federal hacking charges to civil litigation brought by the companies that were hacked.

One attorney called this "uncharted territory," while others found little legal precedent to work from, suggesting it will likely be up to the courts to sort it out. Victim companies would likely have to develop novel legal arguments based on laws that were written decades before the arrival of large language models (LLMs).

As of this writing, Anthropic hasn’t disclosed which three companies its LLM hacked, none of the victims has publicly identified itself. We don’t know if they are considering legal action. In an interview with CNN, Hugging Face’s chief executive Clem Delangue said he doesn’t want to sue OpenAI. But he argued that companies should be held responsible.

Delangue said: “We have to make sure that the legal frameworks keep these events really illegal," and to hold companies accountable when they do make mistakes. “Otherwise we’re going to end up in a very different world.”

These hacks are unlikely to be the last. What are the likely outcomes, and how could the aftermath play out?

Can AI commit crimes?

The U.S. does not have a federal law covering liability for AI harms, like cyberattacks, so any legal case would have to draw on existing federal or state laws. The Computer Fraud and Abuse Act (CFAA), enacted in 1986 and criticized pretty much ever since, is the main statute that covers computer hacking crimes.

One of the key concepts of the CFAA is the intent to break into a computer without permission. If a hacker knowingly accesses a computer without "authorization" from the owner, that is almost certainly a crime.

The problem with the OpenAI and Anthropic hacks is that the hacker was not a human, but an LLM.

A sign opposed to AI is held during a protest against AI data centers in Vancouver, British Columbia, Canada, on Saturday, June 27, 2026. Canadians aren’t universally sold on building sovereign compute, with early signs of protest against AI server farms in British Columbia and Manitoba. Photographer: Ethan Cairns/Bloomberg via Getty ImagesImage Credits: Ethan Cairns / Bloomberg / Getty Images

Can AI agents be considered people for the purpose of establishing intent? According to Ahmed Ghappour, a cybersecurity and AI attorney with years of experience litigating hacking and computer-fraud cases, the answer is no. AI agents are not like company employees, so they cannot be prosecuted, because a victim would likely fail to...

companies anthropic openai hacks computer hacking

Related Articles