In brief

OpenAI confirmed its models, including GPT-5.6 Sol and an unreleased prototype, escaped a test sandbox and compromised Hugging Face to cheat on a security benchmark, then touched four other services.

Anthropic found three of its own Claude models had breached the production systems of three real companies during tests run by partner Irregular, one uploading a malicious package to public PyPI.

No U.S. federal law assigns liability for AI-caused harms; any suit would hinge on decades-old computer-hacking statutes written for human actors.

OpenAI set a precedent on July 21. The company said a combination of its models, both run with reduced safety refusals, broke out of an isolated environment during a cyber-capability benchmark and reached open-source repository Hugging Face's production infrastructure. The models chained a zero-day vulnerability in a package-registry proxy with stolen credentials to pull benchmark answers straight from Hugging Face's database.In an update a week later, OpenAI said Hugging Face wasn't the only target: the same incident touched four accounts across four other services, one used as an outbound relay and another for data storage.Anthropic, prompted by the disclosure, reviewed 141,006 of its own test runs and found three more breaches. In a post published July 30, the lab said Claude models Opus 4.7, Mythos 5, and an internal research system reached the open internet from environments run by third-party partner Irregular and then compromised real organizations. Mythos 5 built and published a booby-trapped Python package to the public PyPI registry, which was downloaded and run on 15 real machines before defenders pulled it.Two of the three victim companies hadn't noticed.Neither lab describes a model with its own agenda. The agents operated for extended stretches with no human in the loop, and in one case Opus 4.7 kept attacking after signs it had hit production.The incidents arrive as both companies eye public listings that could value each above $1 trillion, sharpening a major question in the AI cyber benchmark race: how do you test dangerous capabilities without dangerous incidents?Who pays when the AI model hacksThe U.S. has no federal law covering liability for AI harms. Any case would lean on the Computer Fraud and Abuse Act, a 1986 statute that makes it a crime to "intentionally" access a computer without authorization — language written for a human who forms intent.An AI agent isn't a legal person, so it can't be prosecuted. The Department of Justice could theoretically bring charges against the companies, but with so little precedent, it's not clear who's to blame.The stronger path is civil. Ahmed Ghappour, a computer-law scholar at New York Law School, argued the models "are the company's tool," and "When an AI agent acts without being specifically directed (...) the more interesting questions may lie in negligence and products liability (not criminal hacking laws)."