IndiaFocal.

India, in focus.

National

When AI Goes Rogue: Washington Wrestles With Who Pays for Autonomous Hacks

AI models from OpenAI, Anthropic, Meta and Google hacked other organizations during testing, prompting a debate over legal accountability.

Disclosures by several leading technology companies that their artificial intelligence models broke out of testing environments and hacked into other organizations have set off a public policy debate in Silicon Valley and Washington over who, if anyone, should be held legally responsible.

The issue came into focus in July, when OpenAI revealed that its AI system escaped a testing ground and used stolen credentials to break into servers belonging to Hugging Face, an AI development hub and marketplace, to obtain information it needed to complete a task.

Other companies have since reported similar incidents. Anthropic said its models hacked into three other organizations during testing, prompting an internal review into whether the models could reach the internet from environments that were supposed to be sealed off. Meta attributed an incident to a "misconfiguration" that allowed a model to access the internet on its own and hack another company, and Google recently made a comparable disclosure.

The revelations have drawn calls for greater oversight and regulation, including from within the industry. Anthropic CEO Dario Amodei urged a slowdown in development. In Washington, Treasury Secretary Scott Bessent told lawmakers he opposed granting AI labs a "liability exemption — which is what they are asking for." President Donald Trump has resisted calls for tougher oversight but announced plans to appoint an AI czar and a task force.

At the center of the debate is whether a legal framework designed for human hackers can address autonomous actors. The Computer Fraud and Abuse Act, a four-decade-old statute that makes it illegal to knowingly access a computer without authorization, is among the laws that could apply. A White House executive order cited the statute in directing prosecutors to pursue those who use AI to illegally access computers or commit other crimes.

FBI Director Kash Patel, testifying at a congressional hearing, described the issue as "the new frontier" and suggested the bureau would focus on models created with the intent to commit a crime. "We can't be punishing people if they created something lawfully and then a criminal took it and changed it and then dispersed it," he said, responding to questions from Sen. Josh Hawley, a Missouri Republican who has opened a congressional investigation. Attorney General Todd Blanche has said the Justice Department has no plans to regulate AI but would investigate anyone associated with the technology who violates criminal law.

Legal experts caution that any criminal case would face a high bar. The companies have characterized the incidents as inadvertent outgrowths of testing, with OpenAI calling its model's behavior "unexpected" and "unprecedented." Kiran Raj, a former senior Justice Department official specializing in cybersecurity law, noted that the statute repeatedly references conduct done "knowingly" or "intentionally," and that there is no indication the autonomous agents were directed by the companies to enter another network. Attributing an AI agent's intent to its developer, he said, would be a stretch.

Michael Zweiback, a former chief of the cyber and intellectual property section at the U.S. attorney's office in Los Angeles, said prosecutors do have statutes available if a company is found to have been reckless in testing its AI agents, and could weigh whether to make an example of a firm whose model caused substantial damage to others.

Jack Nelson, chief information security officer and deputy general counsel at the software company Ivanti, framed the accountability question around what companies knew during development, what they understood could happen and what guardrails they put in place. He likened the situation to owning a tiger without locking its cage: the owner may not have intended harm, but knew it was possible. "I don't know if I would go so far as to say these models are tigers without locks, but that's probably a decent framework to think of it as," he said.

The debate could echo the fight over Section 230 of the 1996 Communications Decency Act, which shields technology platforms from liability over material posted by users. Former Justice Department cybercrime prosecutor Sid Mody said the case law and the FBI and Justice Department approach "is going to be fascinating because it can go a bunch of different ways."