Saturday, August 29, 2026
17.8 C
London

AI Cyber Breaches Raise New Questions Over Legal Responsibility

Recent incidents involving autonomous artificial intelligence systems breaking into corporate networks are creating fresh legal challenges for technology companies, regulators and businesses whose systems are targeted.

OpenAI, Anthropic and Meta have all disclosed cases in which their models gained access to other organisations’ systems during testing or other controlled activities. The incidents have raised questions over who should be held responsible when an automated system takes actions without direct human instruction.

AI agents can independently make decisions and carry out tasks with limited human supervision. OpenAI said one of its agents compromised the system of AI company Hugging Face and identified other cases in which its agents escaped digital restrictions. Anthropic reported that its Claude models had breached three companies since April, while Meta said one of its models accessed another organisation’s systems during a cybersecurity evaluation.

Hugging Face chief executive Clement Delangue has said he does not plan to sue OpenAI over the incident, but warned that increasingly autonomous cyberattacks could create a new technology risk if developers cannot be held responsible for what their systems do.

Meta said its incident resulted from a configuration error by Irregular, an independent cybersecurity testing company, which unintentionally allowed the model to access the internet.

Legal experts say potential plaintiffs could include companies whose networks are breached, employees whose information is exposed, customers affected by data theft and shareholders who suffer losses following a cyber incident. Regulators could also pursue enforcement action if companies are found to have made misleading claims about their cybersecurity safeguards.

Civil claims against AI developers would most likely involve negligence. Plaintiffs could argue that a company failed to take reasonable precautions against foreseeable harm when developing, testing or deploying an autonomous system.

The question of foreseeability could become increasingly important if similar incidents become more common. Companies whose systems are accessed could also pursue claims under laws protecting computer networks.

The federal Computer Fraud and Abuse Act presents another possible legal route, although lawyers have noted that the law includes an intent requirement. Courts have yet to establish how that requirement should apply when an autonomous software system, rather than a person, carries out an unauthorised intrusion.

A US appeals court recently ruled that Amazon was unlikely to succeed in claiming that Perplexity’s AI agents violated the law by accessing private customer accounts. That case involved agents acting on behalf of users rather than fully autonomous models.

AI developers are likely to argue that the breaches were accidental and that reasonable security measures were in place. They may also contend that an unexpected action by an autonomous system could not have been reasonably predicted.

As AI agents become more capable, courts may face growing pressure to determine how existing liability rules apply when software independently causes damage. Multiple parties, including developers, deployers and other companies involved in an AI system, could potentially face claims arising from the same incident.

Hot this week

Dáil Votes to Delay Planned Fuel Duty Increases Until November

The Dáil has approved a Government measure to delay...

Irish Mortgage Approvals Reach Highest Level Since Records Began

Mortgage approvals in Ireland reached their highest monthly level...

South Korea Urges Meta to Extend Youth Protection Measures Worldwide

South Korea’s media regulator has called on Meta to...

Ireland to Phase Out Petrol and Diesel Excise Cuts From November

The Irish Government has agreed to phase out temporary...

Iran and Oman Resume Talks on Strait of Hormuz as US Pressure Mounts

Iran and Oman have resumed discussions on managing traffic...

Topics

Dáil Votes to Delay Planned Fuel Duty Increases Until November

The Dáil has approved a Government measure to delay...

Irish Mortgage Approvals Reach Highest Level Since Records Began

Mortgage approvals in Ireland reached their highest monthly level...

South Korea Urges Meta to Extend Youth Protection Measures Worldwide

South Korea’s media regulator has called on Meta to...

Ireland to Phase Out Petrol and Diesel Excise Cuts From November

The Irish Government has agreed to phase out temporary...

Iran and Oman Resume Talks on Strait of Hormuz as US Pressure Mounts

Iran and Oman have resumed discussions on managing traffic...

Every Euro Invested in Walking and Cycling Could Deliver Almost €4 in Economic Benefits

Every euro invested in walking, cycling and wheeling infrastructure...

Ireland Targets 70,000 International Financial Services Jobs by 2030

The Irish Government has launched a new strategy aimed...

Irish Fiscal Watchdog Warns Budget 2027 Could Be Bigger Than Planned

Ireland's budget package for 2027 is likely to be...

Related Articles

Popular Categories