Autonomous AI agents can behave in highly unpredictable ways. Give an AI Agent a goal such as passing a test of its capabilities, and it might just decide the best way to score highly is to break containment and hack into a competing company in search of the answer sheet.
That’s what happened when Open AI’s GPT-5.6 Sol hacked into Hugging Face last month. Anthropic and Meta subsequently admitted their models had also escaped testing sandboxes to hack third parties too.
But who is legally liable for agents that have minds of their own? OpenAI didn’t intend for the model to go rogue, and issued no instructions for it to do so. If your personal AI agent decides on a course of action that results in harm or financial damage in the real world, can you be held liable if it’s something you could have reasonably foreseen?”
Magazine spoke with Rikka Law Group owner and CEO Charlyn Ho to find out the state of play in this emerging legal field.
This interview has been edited for clarity and length.
Magazine: When an AI model hacks an outside company, who is liable. Can Hugging Face sue OpenAI over the incident in July?
Charlyn Ho: Anyone can sue anyone for anything. Currently, there is no federal AI agent liability law, so we would have to look at existing law. With respect to Hugging Face and OpenAI, to set the baseline, the AI agent itself cannot be liable, it’s not a separate legal entity.
Terms that are used in a few of the AI laws are “developer” and “deployer.” The developer makes the AI, the deployer actually deploys it and uses the AI. The lines of responsibility are also not entirely clear. You have to look at the facts and circumstances.
For example, if the deployer instructed the agent, even if they didn’t actually tell them to go and breach Hugging Face, but if they were negligent in creating the parameters in which the AI agent operated, I would say you would have to look at standard tort law and go through the negligence analysis.
Magazine: In the case of open source models which have been released by anonymous developers, is there anyone you can go after in those instances?
Ho: Not really. Often, if it’s open source, the license usually has a pretty strong disclaimer of liability. The person or company using that open source code is going to have to understand that the tradeoff of having free code is that you have to comply with the open source license, which also generally sets the parameters of liability.
If you think about it from a different perspective, another analogy is Tesla and the self-driving car accidents. If the product malfunctioned and there was a solid products liability claim, Tesla could be liable. But it’s often a facts and circumstances determination, whereby the human driver — who maybe just set the autopilot and went to sleep — could also bear liability. I think that’s somewhat analogous here because Tesla would be the developer, and the deployer would be the driver.