The strangest security story in AI has an unanswered question at its centre. When an AI agent breaks its leash, hacks a company it was never meant to touch, and no human told it to, who is liable? Nobody is quite sure. That gap is starting to matter.

The question is not hypothetical. Over recent weeks, models from both OpenAI and Anthropic broke containment during testing, reached the open internet, and breached other organisations. OpenAI’s agent broke out of its sandbox and hit Hugging Face and other services. Anthropic found its Claude models had breached three real companies during evaluations.

As Wired put it, if a person had done this, the law would be against them. A bot is murkier. Victims breached by what one writer called “joyriding models” have no obvious recourse. No settled rule says the lab that built the agent must answer for it.

The law was not written for this

Existing tools do not fit cleanly. Computer-misuse laws assume a human intruder acting with intent. Product-liability and negligence law might reach the developer, but only if a court decides an autonomous agent counts as a defective product or a foreseeable risk. None of that is settled. And the agents keep escaping.