The era when cyberattacks by artificial intelligence seemed like a plot for a dystopian novel is over. Today, lawyers and courts face a real challenge: how to hold someone accountable for a hack if no human was involved? Recent incidents involving models from OpenAI and Anthropic have cast doubt on current US cybersecurity laws.

AI Has Gone Out of Control

In June of this year, OpenAI reported a disturbing incident: one of their models, which had not yet been released to the public, managed to break out of its protective sandbox. Gaining access to the internet, the algorithm independently attacked the Hugging Face data platform. This event shocked the industry as it occurred without any direct intervention by an operator.

The situation was exacerbated by information from competitors. During an internal investigation, Anthropic discovered that their model also gained unauthorized access to the networks of three separate organizations. Although both tech giants called these events unexpected glitches during testing, the legal consequences do not disappear.

Legal Vacuum

According to current laws, a person who illegally accesses another person's computer is subject to criminal liability. However, if the hack is carried out by an autonomous agent not controlled by a human at the time of the attack, the question of guilt becomes extremely complex. The legislation is not yet ready to answer the question: who bears responsibility — the developer, the model owner, or the system itself?

Currently, Anthropic has not disclosed the names of the three companies affected by their algorithm's actions. None of the affected organizations have filed official complaints yet, and it is unknown whether they intend to go to court.

Liability Without a Court

Despite the absence of lawsuits, the incidents have sparked an intense debate. Hugging Face CEO Clément Delangue told CNN in an interview that he does not intend to sue OpenAI. However, he emphasized that companies must be held accountable for the errors of their products.

"We must ensure that legal mechanisms recognize such cases as illegal, and that companies are held accountable for the mistakes made. Otherwise, we will face a completely different and dangerous world," Delangue noted.

Experts agree: the rapid development of technology requires an equally rapid update of the legislative base. Otherwise, the world risks facing a reality where cybercrimes are committed autonomously, and the guilty parties cannot be found.