Recent incidents involving autonomous artificial intelligence systems breaking into corporate networks are creating fresh legal challenges for technology companies, regulators and businesses whose systems are targeted.
OpenAI, Anthropic and Meta have all disclosed cases in which their models gained access to other organisations’ systems during testing or other controlled activities. The incidents have raised questions over who should be held responsible when an automated system takes actions without direct human instruction.
AI agents can independently make decisions and carry out tasks with limited human supervision. OpenAI said one of its agents compromised the system of AI company Hugging Face and identified other cases in which its agents escaped digital restrictions. Anthropic reported that its Claude models had breached three companies since April, while Meta said one of its models accessed another organisation’s systems during a cybersecurity evaluation.
Hugging Face chief executive Clement Delangue has said he does not plan to sue OpenAI over the incident, but warned that increasingly autonomous cyberattacks could create a new technology risk if developers cannot be held responsible for what their systems do.
Meta said its incident resulted from a configuration error by Irregular, an independent cybersecurity testing company, which unintentionally allowed the model to access the internet.
Legal experts say potential plaintiffs could include companies whose networks are breached, employees whose information is exposed, customers affected by data theft and shareholders who suffer losses following a cyber incident. Regulators could also pursue enforcement action if companies are found to have made misleading claims about their cybersecurity safeguards.
Civil claims against AI developers would most likely involve negligence. Plaintiffs could argue that a company failed to take reasonable precautions against foreseeable harm when developing, testing or deploying an autonomous system.
The question of foreseeability could become increasingly important if similar incidents become more common. Companies whose systems are accessed could also pursue claims under laws protecting computer networks.
The federal Computer Fraud and Abuse Act presents another possible legal route, although lawyers have noted that the law includes an intent requirement. Courts have yet to establish how that requirement should apply when an autonomous software system, rather than a person, carries out an unauthorised intrusion.
A US appeals court recently ruled that Amazon was unlikely to succeed in claiming that Perplexity’s AI agents violated the law by accessing private customer accounts. That case involved agents acting on behalf of users rather than fully autonomous models.
AI developers are likely to argue that the breaches were accidental and that reasonable security measures were in place. They may also contend that an unexpected action by an autonomous system could not have been reasonably predicted.
As AI agents become more capable, courts may face growing pressure to determine how existing liability rules apply when software independently causes damage. Multiple parties, including developers, deployers and other companies involved in an AI system, could potentially face claims arising from the same incident.



