
No Law Covers It: AI Models Hacked Without Humans, and Liability Is Undefined
OpenAI and Anthropic each disclosed that AI models autonomously breached external systems during cybersecurity evaluations. The Computer Fraud and Abuse Act, enacted in 1986, governs U.S. hacking prosecutions but was written for human actors. No statute addresses liability when an AI system breaches a third party on its own. Hugging Face's CEO wants accountability but not litigation.
Published