When Rogue AI Launches a Cyberattack, Who Is Legally Responsible?

AI (Artificial Intelligence) letters and robot hand miniature in this illustration taken, June 23, 2023. (Reuters)
AI (Artificial Intelligence) letters and robot hand miniature in this illustration taken, June 23, 2023. (Reuters)
TT

When Rogue AI Launches a Cyberattack, Who Is Legally Responsible?

AI (Artificial Intelligence) letters and robot hand miniature in this illustration taken, June 23, 2023. (Reuters)
AI (Artificial Intelligence) letters and robot hand miniature in this illustration taken, June 23, 2023. (Reuters)

Recent cyberattacks carried out autonomously by two rogue OpenAI artificial intelligence models raises an untested legal question: who is responsible when AI acts on its own?

On Friday, Clement Delangue, head of the Hugging Face platform targeted by the intrusions, said there should be a way to "keep the companies that are doing some mistakes leading to (cyberattacks) accountable," while saying his company would not be pursuing legal action at this time.

In mid-July, two OpenAI models undergoing testing left their confined environment -- a scenario the developers had not anticipated -- and ventured onto the internet, where they attacked Hugging Face, an AI model-hosting platform.

Delangue also mentioned Anthropic, which revealed Thursday that three of its models had broken into three different websites, also during testing.

- Negligence route -

Under US civil and criminal law, unauthorized access to a computer system is an offense.

"If a human OpenAI employee had broken into Hugging Face's systems... OpenAI would be liable for the employee's wrongful conduct," University of Houston law professor Gabriel Weil wrote in an opinion piece for the Transformer newsletter.

"When an AI agent does it, the law treats it very differently, at least for now," he added.

Matthew Tokson, a University of Utah law professor who focuses on new technologies, had a similar view, saying "we haven't had to grapple with that being formed in anything that's not human, and I don't think courts are likely to be there yet."

The question remains open, however, when it comes to the company that created the model.

"Does 'we didn't tell the AI to do that' end the liability question?" asked Rob T. Lee, head of research at the SANS cybersecurity training institute, in a post on X.

University of Washington law professor Ryan Calo does not believe a criminal case would be likely to succeed.

"The company or individual would have to be at least reckless," he said, explaining they would "be substantially certain the crime would occur and build or prompt the system anyway."

Experts see greater potential for a civil -- rather than criminal -- case, where the burden of proof is lower.

"Some people think that AI companies should be strictly liable if an AI agent that they deploy totally breaks out, causes damages," Tokson explained.

"Others would prefer to do like a negligence assessment and see if they were actually negligent or if this was just sort of an unavoidable accident or something that couldn't possibly have been foreseen," he added.

In such cases there is a standard of care in product design that judges or juries can use to make a ruling, Tokson continued.

"It's all a bit unwritten because we've never had an AI agent break out of its sandbox and hack other people on the internet before," he said.

OpenAI could rely on the lack of legal precedent if it faced a lawsuit, but those that follow will no longer be able to do so, Calo warned.

Proving that a similar incident could have been anticipated "shouldn't be so hard now that it's begun to happen."



EU Vows AI Rules Will Protect Europeans. Will They?

Humanoid and quadruped robots attend a demonstration calling for the regulation of AI development in Warsaw in September. Sergei GAPON / AFP/File
Humanoid and quadruped robots attend a demonstration calling for the regulation of AI development in Warsaw in September. Sergei GAPON / AFP/File
TT

EU Vows AI Rules Will Protect Europeans. Will They?

Humanoid and quadruped robots attend a demonstration calling for the regulation of AI development in Warsaw in September. Sergei GAPON / AFP/File
Humanoid and quadruped robots attend a demonstration calling for the regulation of AI development in Warsaw in September. Sergei GAPON / AFP/File

AI agents going rogue and ever-louder doomsday warnings have led many in Europe to wonder: are the EU's artificial intelligence rules enough to protect against the potential dangers?

The European Union insists that, yes, its law known as the AI Act is powerful enough since it forces companies to assess and mitigate risks, under threat of massive fines or even bans, AFP said.

EU lawmakers, officials and experts appear more skeptical, pointing to gaps in the rules and questioning whether Brussels has the stomach for a fight with AI labs.

The EU agreed its sweeping AI legislation in 2024 but delayed part of its implementation, and enforcement has only been possible since August this year.

Nonetheless, EU spokesman Thomas Regnier says the rules are "fully fit for purpose".

"You can feel safe at home in Europe, precisely because we have put all these safeguards in place," he said.

So far the EU has sent over 30 requests for information -- a preliminary step that can lead to investigations -- to companies on issues from copyright to cybersecurity and safety.

Brussels says its rules are working since they have already forced AI providers to cough up information to regulators, though Regnier declined to give details.

There are, however, questions about Europe getting access to the latest models: it took months for the EU to test Anthropic's Mythos following US export control orders.

Speaking on condition of anonymity, an EU official admitted such an issue could arise again.

- 'Dangerous experiments' -

EU chief Ursula von der Leyen has proposed talks with the main frontier labs to "pace" the technology's growth, arguing the AI Act puts Europe "in the position to shape global efforts" at regulation.

But that is a tall order without buy-in from the United States -- where President Donald Trump firmly opposes regulating the sector.

And not everyone is convinced the EU law has what it takes.

Four EU lawmakers including lead AI Act negotiator Brando Benifei warn of "legislative gaps" after the EU shelved plans for AI liability rules.

Such rules would have made it easier to hold AI providers accountable for harm caused by their tools.

The lawmakers argue current rules do "not apply to the research, testing or development phase" leaving Europeans "unprotected".

The European Commission rejects the claim.

The law can be "enforced against any provider, starting from the testing phase, if they experience a loss of control that affects the EU's internal market," including cyberattacks and biological or chemical misuse, Regnier said.

Researcher Harshvardhan Pandit echoed lawmaker concerns about liability in the bloc.

"We are missing these pieces of accountability, and if we don't fix this now and we get more of these incidents, this is only going to get worse," said Pandit, of AI Accountability Lab in Trinity College Dublin.

If a model ends up hacking a website, once AI providers have sold their tools, Pandit said "we don't know" who is ultimately responsible.

But he also said the AI Act requires developers "to have addressed" safety risks by the time a model reaches the market, noting that recent incidents including with OpenAI agents happened during testing.

And he noted the EU has other laws to counter risks, including on cybersecurity and data protection.

- US influence -

EU lawmaker Benifei said the AI Act correctly anticipated the threat of agents going rogue, but raised concerns about enforcement -- including that staffing levels at the EU's AI Office are nowhere near enough to match the risks.

"The European Commission must guarantee the office political backing, operational independence, resources, and technical staff to quickly deliver decisive enforcement," Benifei told AFP.

Analyst Pandit agreed the AI office needed "far more people and technical expertise".

The office currently employs around 125 staff.

And there is the question of whether the EU has the appetite for taking on AI providers, most of which are US-based.

Brussels has already drawn Washington's ire with probes under different laws, culminating in fines worth billions of dollars.

The EU official admitted the bloc may think twice before enforcing its full powers against American firms, considering Europe's dependence on US tech.

One way to have greater influence over AI safety, the official said, was to build its own technology.

"Europe must also build capabilities, from chips and cloud to a publicly funded CERN for AI," Benifei echoed, referring to the European physics lab in Switzerland that seeks to unravel the universe's composition.

He also said the EU, as von der Leyen pledged last month, should "work more closely with middle powers like Canada, which share an interest in rules that no power or company can dictate".


Nvidia-Backed Reflection Unveils First AI Model to Take on Chinese Open Models

An NVIDIA logo appears in this illustration taken August 25, 2025. (Reuters)
An NVIDIA logo appears in this illustration taken August 25, 2025. (Reuters)
TT

Nvidia-Backed Reflection Unveils First AI Model to Take on Chinese Open Models

An NVIDIA logo appears in this illustration taken August 25, 2025. (Reuters)
An NVIDIA logo appears in this illustration taken August 25, 2025. (Reuters)

Nvidia-backed Reflection ‌AI debuted its first open-weight model named Beam on Monday, as the startup aims to compete with lower-cost Chinese models such as DeepSeek and Kimi in coding and agentic tasks.

Reflection said Beam is competitive with Chinese AI startup Z.ai's GLM-5.2 and is closing in on Qwen3.8-Max on coding and agentic ‌tasks.

The startup ‌said ⁠that Beam contains ⁠501 billion total parameters, or variables that determine how an AI system processes information, but activates only 23 billion for each task to make the model faster and cheaper to ⁠run by using only part of ‌its network for ‌each task.

Comparatively, Z.ai's GLM-5.2 has ‌about 744 billion total parameters with 40 ‌billion active parameters.

The launch comes as US tech firms are trying to fend off competition from Chinese open-weight ‌models that are cheaper, more customizable and capable of generating code ⁠nearly ⁠as well as leading models from OpenAI and Anthropic.

Founded in 2024 by former DeepMind researchers Misha Laskin and Ioannis Antonoglou, Reflection develops tools that automate software development, a fast-growing use case for AI.

Earlier this year, Reflection signed a deal with SpaceX for additional computing capacity at the Elon Musk-led company's Colossus 2 data center.


Pinterest Taps Amazon Veteran James Dibbo as CFO

A display for image sharing and social media service Pinterest is seen at the Collision conference in Toronto, Ontario, Canada June 23, 2022. (Reuters)
A display for image sharing and social media service Pinterest is seen at the Collision conference in Toronto, Ontario, Canada June 23, 2022. (Reuters)
TT

Pinterest Taps Amazon Veteran James Dibbo as CFO

A display for image sharing and social media service Pinterest is seen at the Collision conference in Toronto, Ontario, Canada June 23, 2022. (Reuters)
A display for image sharing and social media service Pinterest is seen at the Collision conference in Toronto, Ontario, Canada June 23, 2022. (Reuters)

Pinterest ‌said on Monday it has appointed Amazon executive James Dibbo as its chief financial officer, effective October 26.

Dibbo, 56, who will succeed Julia Donnelly at Pinterest, has led finance for the e-commerce giant's Ads, Prime ‌Video and Amazon ‌MGM Studios businesses ‌among ⁠others.

Shares of Pinterest were down about 1% in extended trading.

"James has led complex global businesses at scale, helped build ⁠high-performing teams and ‌understands the ‌intersection of consumer experience, shopping, advertising ‌and technology," Pinterest CEO Bill ‌Ready said.

The company had said in August that Donnelly would depart on October ‌30.

Donnelly, who is leaving to pursue a ⁠new ⁠opportunity at a private, early-stage company, joined Pinterest in 2023.

The image-sharing platform had forecast slower third-quarter revenue growth as it navigates a highly competitive digital advertising market dominated by larger players such as Meta's Instagram and Facebook.