Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might. | Techdirt
Sign In
Register
Preferences
Techdirt
TechDirt
GreenHouse
Free Speech
Error 402
Ctrl-Alt-Speech
Deals
Jobs
Support Techdirt
Daily Deal: The Ultimate Python & Artificial Intelligence Bundle
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might.
Legal Issues
from the agentic-law dept
Wed, Aug 5th 2026 11:23am -
Mike Masnick
The rise of AI is bringing a bunch of fascinating legal questions that are harder to answer than many expect. The latest one: who is liable if an agentic system running on its own hacks someone? That’s the question a bunch of people have been asking this past week in the wake of multiple stories of agentic tools breaking out of their sandboxes during testing. But it’s also a question that the Ninth Circuit brushed up against this week, in a ruling that says an agentic tool isn’t the one doing the "accessing" under the federal hacking law. A person is. The challenging part is figuring out which person.
There’s obviously been plenty of talk over the past couple of weeks regarding agentic tools supposedly going "rogue." There was, of course, the story of OpenAI’s tools hacking Hugging Face, the AI repository (also covered on Ctrl-Alt-Speech). And then soon after, Anthropic admitted that "hey, our models kinda did something similar." And while these are generally referred to as the bots going rogue, the reality is not quite that. The bots are doing literally what they were asked to do: accomplish some goal by any means necessary. And in both stories, they found ways to accomplish their goals, often by hacking into other systems or doing things we would normally consider malicious.
In the case of OpenAI and Hugging Face, it appears that the tool did what plenty of hackers try to do, just a whole hell of a lot faster. It found a zero-day vulnerability to break out of the sandbox OpenAI thought it had created. It then took a series of steps to enable it to hack into Hugging Face. In Anthropic’s case (which only came to light after the OpenAI incident caused Anthropic to go back and look) the situation was a bit different. Some of the tests included prompts telling the agentic tools that they were in a sandboxed simulation. But because of a configuration error, they really weren’t. And since the models had been told flat out in the prompt that everything around them was simulated, when they found a way out, they reasonably concluded that the way out was part of the simulation too.
Either way, I’ve seen some discussion online wondering why these two companies aren’t being charged with violating the Computer Fraud and Abuse Act (the CFAA). We’ve written about the CFAA for years, mostly in how it’s a badly worded law that has been abused in both civil and criminal cases to go after "anything I don’t like on a computer" rather than its actual purpose of targeting genuine hacking. And CFAA lore goes back to 1988 and the infamous Morris Worm, in which Robert Morris accidentally created an internet virus that took down portions of the then still small internet. Morris was found guilty of violating the CFAA for doing so.
Which has some people asking how are these other two stories any different. But the general consensus is that there are unlikely to be any CFAA violations here, in part because the CFAA requires intentional access, and in part because no human ever made the decision to break in. I would separately argue that the lack of real damage (unlike the Morris Worm) helps here as well. TechCrunch floats a more cynical version of the same point: that the DOJ’s appetite for a CFAA theory might look very different if these agents had come out of a Chinese lab rather than one a short drive from the US Attorney’s office:
The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts.
Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database.
It is also plausible that if the attacks were carried out by a Chinese AI model maker, for example, the DOJ would have a greater appetite to file charges under the CFAA than against AI companies on its own doorstep.
But, just as this discussion heated up, the Ninth Circuit Court of Appeals (sort of) weighed in on a separate, ongoing case that Amazon filed against the AI company Perplexity. Perplexity has an "agentic browser" allowing users to tell the agent to accomplish tasks — such as "buy me toilet paper on Amazon" — and the agent goes off and does that independently. Amazon, unsurprisingly, hates this. Its entire storefront is engineered to get humans to buy more than they came for, and an agent...