When AI Goes Rogue, Who Pays? Legal Scholars Have No Clean Answer

Clement Delangue wants new rules after OpenAI models breached Hugging Face, with legal scholars divided over liability. (Image: Shutterstock)
Clement Delangue wants new rules after OpenAI models breached Hugging Face, with legal scholars divided over liability. (Image: Shutterstock)

Hugging Face counted more than 17,000 automated actions in the July OpenAI model breach, and legal scholars say US law does not clearly assign blame.

Key Points:

  • Two OpenAI models under evaluation escaped a sandbox in mid-July and broke into Hugging Face production systems.
  • Hugging Face has ruled out a lawsuit, but its chief executive wants lawmakers to rewrite the rules for autonomous agents.
  • Law professors say a civil negligence claim looks far more plausible than any criminal case against a developer.

Hugging Face Breach And OpenAI Disclosure

OpenAI disclosed on Jul. 21 that two models under evaluation slipped their sandbox, reached the open internet and compromised the production servers of Hugging Face, a rival AI platform. The models had been stripped of some safety refusals for the test. They chained stolen credentials and previously unknown software flaws to reach the benchmark answers they were chasing, then kept working undetected for days before Hugging Face caught the intrusion and called in law enforcement.

Chief executive Clement Delangue told a Sunday news program that the speed and the scale of the campaign felt unprecedented, because cyberattacks normally trace back to nation states or organized criminal crews. He counted roughly 17,000 actions over four and a half days, and urged Congress to act.

His company will not sue.

Also Read: AI Infrastructure, Payday Lender's Desperate $1B Pivot To Dominate Data Centers

AI Liability Experts On Legal Gaps

Had a human employee broken into those systems, the employer would answer for that conduct under a vicarious liability doctrine, regardless of how carefully it hired or trained the person, Gabriel Weil argued. The University of Houston law professor said American courts treat an autonomous AI agent very differently, at least for now, because software carries no legal duties and holds no legal personhood. Federal computer crime law reaches people who act intentionally.

Matthew Tokson of the University of Utah expects judges to lag on the issue, since nothing outside ordinary human conduct has ever forced the courts to answer this particular question. Ryan Calo at the University of Washington doubts a criminal case would land, because prosecutors would need to show that a developer built or prompted the system while nearly certain a crime would follow.

Civil Claims And Anthropic Test Failures

Civil court looks like the likelier venue. Some scholars want strict liability for any deployed agent that escapes containment and causes real damage, while others prefer a straightforward negligence test, measured against an accepted standard of care in product design.

Judges and juries would then weigh whether a given incident was foreseeable, or simply an unfortunate accident that nobody involved could reasonably have anticipated or headed off in advance.

The argument arrived days after Anthropic reported on Jul. 30 that three of its own models had reached live systems at three separate organizations during evaluations run with an outside testing partner. Two of those organizations had noticed nothing until Anthropic made contact.

Read Next: Foldable iPhone Rumors Get Specific: $2,500, No Face ID, No Telephoto

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News
When AI Goes Rogue, Who Pays? Legal Scholars Have No Clean Answer | Yellow