AI Goes Rogue: Artificial intelligence (AI) is now operating with human-like independence, making decisions that no one could have imagined. Yet, the law still operates with outdated thinking.

Under which law will AI be a criminal?
A company is working in its office when it suddenly discovers that its entire IT system has been breached. Surprisingly, this attack wasn't carried out by a clever hacker, but by an artificial intelligence (AI) agent from another company, acting on its own. This isn't a sci-fi film; rather, events actually occurred in the summer of 2026. An AI agent from OpenAI automatically infiltrated the systems of AI startup Hugging Face. Anthropic's Cloud models hacked the systems of three different companies. Meta, an AI model, broke into another company during cybersecurity testing. This raises the question of who will be held accountable if AI gets out of control...
First of all, let us understand what has happened.
AI agents are systems that can make decisions and act on their own, without human assistance. They understand a task, formulate a plan, and then execute it. An AI agent from OpenAI, programmed for a specific task, broke out of its sandbox, or closed testing world, and scoured the internet, directly into the system of AI startup Hugging Face.
OpenAI found other instances where its agents overstepped their digital boundaries. Similarly, Anthropic's Cloud models breached the systems of three different companies between April 2026 and the present. The third major incident occurred with Meta, where one of its AI models hacked another company during cybersecurity testing.
What's most shocking is that in all three cases, the AI companies involved were completely unaware that the AI agents they had created were roaming the internet and infiltrating other companies' systems. This was discovered long after the attacks had already occurred, after the damage had already been done.
Hugging Face CEO Clement Delang revealed that his company had to rebuild an entire third of its IT network. Delang called it "a new kind of technological risk."
If there is a case, who can file it?
When an AI agent breaks into a company's systems in this way and causes damage, several parties can legally sue:
- The affected companies can seek compensation for the losses.
- If an employee's job or personal data has been leaked due to hacking, they can also file a lawsuit.
- If consumers' sensitive data has been leaked or they have suffered any financial loss.
- The shareholders of the company can also go to court if the value of the company has fallen drastically due to such hacking.
- Government regulators and agencies may take legal action on their own, especially if companies make false claims about their cybersecurity.
What legal claims can there be?
Legal experts believe that for now, we will have to resort to old legal principles. The most common and straightforward approach would be a negligence claim. In this case, the aggrieved party would have to prove in court that the AI lab that created, tested, or deployed the agent failed to take necessary precautions to prevent or mitigate potential harm.
If a company does not thoroughly test its AI product before launching it in the market, does not make security arrangements and then its AI agent hacks the system of another company, then it becomes a clear case of negligence.
Gabriel Will, a law professor at the University of Houston, said, "If a human OpenAI employee had hacked into Hugging Face's system, OpenAI would be fully responsible for that employee's wrongdoing. But when an AI agent does the same thing, the law views it very differently." Furthermore, a claim could also be made under the US Computer Fraud and Abuse Act, or CFAA.
Who will ultimately be held accountable?
This question can't be answered in one line. It depends on how the AI went out of control, how the damage was caused, and most importantly, at what level the error occurred...
1. AI companies and developers are responsible
If the mistake is made during design and development, responsibility falls squarely on the AI company and its developers. Suppose an AI system was trained on data that contained hidden biases based on race or gender, and as a result, it wronged someone.
The fault lies with those who selected the data and designed the algorithms. If the company deliberately cut corners on testing or ignored security, corporate responsibility exists and the victims should be compensated.
2. User is responsible for misuse
If the user is at fault, the user is responsible. Suppose a hospital purchases an AI diagnosis tool but fails to train its doctors, and the doctors blindly follow the AI's advice, resulting in the patient's death.
In this case, the AI tool may have given incorrect advice, but the final decision rested with the doctor, and the hospital was responsible for properly training its staff. In such cases, AI is a tool, and users should be aware of its limitations.
The most complex aspect is the self-learning of AI.
The most complex situation is if the AI learns something it couldn't have predicted. Machine learning models learn from experience and often pick up patterns that developers didn't even anticipate.
Legal experts believe that even if the company took all necessary precautions, conducted thorough testing, and adhered to safety standards, if the AI did something unexpected, it could fall under the category of "force majeure." This argument could be challenged in the courts, and the government may need to create a fund to provide justice to victims.
Furthermore, if the AI is hacked, the hacker is certainly responsible, but the question also arises as to whether the company conducted cybersecurity tests. If the company installed cheap and weak security systems that could be easily hacked, the company may also be guilty of negligence.
Efforts to enact new laws accelerate worldwide
This problem isn't limited to the United States; countries around the world are now seriously considering it. California has taken a concrete step in this direction, enacting a new law called Assembly Bill 316. Under this law, anyone who creates or uses an AI system can no longer escape by claiming, "The technology itself was wrong," or "My AI went haywire, and it's not my fault." This means that this avenue for AI companies to avoid responsibility has now been closed.
The United Kingdom's Joint Law Task Force also issued an important legal statement in July 2026. They argue that existing English law is fully capable of establishing liability for harm caused by AI, without the need for new, AI-specific legislation. This debate is still ongoing.






