Skip to Content Subscribe Our Offers My Account Manage My Subscriptions FAQ Newsletters Canada Canadian True Crime Canadian Politics Health World Israel & Middle East Financial Post NP Comment Longreads Puzzmo Diversions Comics NP News Quiz New York Times Crossword Horoscopes Life Eating & Drinking Style Sponsored Play for Ontario Travel Travel Canada Travel USA Travel International Cruises Travel Essentials Culture Books Celebrity Movies Music Theatre Television Business Essentials Advice Lives Told Tails Told Shopping Buy Canadian Home Living Outdoor Living Kitchen & Dining Tech Style & Beauty Personal Care Entertainment & Hobbies Gift Guide Travel Guide Amazon Prime Day Deals Savings National Post Store More Sports Hockey Baseball Basketball Football Soccer Golf Tennis Driving Vehicle Research Reviews News Gear Guide Obituaries Place an Obituary Place an In Memoriam Classifieds Place an Ad Celebrations Working Business Ads Archives Healthing Epaper Manage Print Subscription Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ Newsletters Canada World Financial Post NP Comment Longreads Puzzmo Diversions Life Shopping Epaper Manage Print Subscription HomeNewsWorldWho is legally liable after a cyberattack by rogue AI?Under U.S. civil and criminal law, unauthorized access to a computer system is an offence, but experts see the former as having greater potential for successAuthor of the article: You can save this article by registering for free here. Or sign-in if you have an account.In July 2026, two OpenAI models undergoing testing left their confined environment — a scenario the developers had not anticipated. Photo by Martin LELIEVRE /AFPRecent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raise an untested legal question: who is responsible when AI acts on its own?Enjoy the latest local, national and international news.Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.Unlimited online access to National Post.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles including the New York Times Crossword.Support local journalism.Enjoy the latest local, national and international news.Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.Unlimited online access to National Post.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles including the New York Times Crossword.Support local journalism.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountorOn Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to “keep the companies that are doing some mistakes leading to (cyberattacks) accountable,” while saying his company would not be pursuing legal action at this time.In mid-July, two OpenAI models undergoing testing left their confined environment — a scenario the developers had not anticipated — and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.Get a dash of perspective along with the trending news of the day in a very readable format.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of NP Posted will soon be in your inbox.We encountered an issue signing you up. Please try againDelangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.Negligence routeUnder U.S. civil and criminal law, unauthorized access to a computer system is an offence.“If a human OpenAI employee had broken into Hugging Face’s systems… OpenAI would be liable for the employee’s wrongful conduct,” University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter. Hugging Face CEO Clement Delangue said his company would not pursue legal action after falling victim to a cyberattack. (CHIP SOMODEVILLA/GETTY IMAGES NORTH AMERICA/AFP) Photo by CHIP SOMODEVILLA /GETTY IMAGES NORTH AMERICA/AFP“When an AI agent does it, the law treats it very differently, at least for now,” he added.Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying “we haven’t had to grapple with that being formed in anything that’s not human, and I don’t think courts are likely to be there yet.”The question remains open, however, when it comes to the company that created the model.“Does ‘we didn’t tell the AI to do that’ end the liability question?” asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.“The company or individual would have to be at least reckless,” he said, explaining they would “be substantially certain the crime would occur and build or prompt the system anyway.”Experts see greater potential for a civil — rather than criminal — case, where the burden of proof is lower.“Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages,” Tokson explained.“Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn’t possibly have been foreseen,” he added.In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.“It’s all a bit unwritten because we’ve never had an AI agent break out of its sandbox and hack other people on the internet before,” he said.OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.Proving that a similar incident could have been anticipated “shouldn’t be so hard now that it’s begun to happen.”Our website is the place for the latest breaking news, exclusive scoops, longreads and provocative commentary. Please bookmark nationalpost.com and sign up for our daily newsletter, Posted, here. Join the Conversation This website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.
Who is legally liable after a cyberattack by rogue AI?
Some are asking who is legally responsible after AI models escaped their training ground and conducted cyberattacks on third parties.
OpenAI and Anthropic models autonomously breached external sites in July 2026, raising the first real-world question: who is liable for rogue AI? Civil liability is more viable than criminal prosecution, but current law leaves a gap—companies may evade accountability by claiming "we didn't direct the AI", creating major compliance and governance risk.











