Who is legally liable when an AI agent goes rogue?

cointelegraphPublicado a 2026-08-28Actualizado a 2026-08-28

Resumen

When autonomous AI agents behave unpredictably and cause harm, determining legal liability is complex. Currently, there is no specific federal AI agent liability law, so existing legal frameworks are applied. The AI agent itself cannot be held liable, as it is not a legal entity. Liability typically falls on the "developer" (the maker of the AI) or the "deployer" (the user), depending on the facts and circumstances. A negligence analysis under standard tort law may apply. For instance, if a deployer gives a reckless instruction, such as demanding quick money without safety parameters, they could face significant liability, including potential criminal charges under statutes like the Computer Fraud and Abuse Act. The situation is complicated by open-source models, where licenses often disclaim liability, and by the unclear division of responsibility between developers and deployers. An analogy is drawn to self-driving car accidents, where both the manufacturer and the human operator can share fault. In cases of severe harm, such as using AI to create bioweapons, liability for developers depends on jurisdiction; the EU's AI Act imposes responsibilities, while U.S. law offers less clear grounds, similar to platforms being shielded for user-generated content under Section 230. Even if Artificial General Intelligence (AGI) is achieved, the expert argues against making AGI itself a legally liable entity, as it lacks personhood, assets, or a meaningful way to provide remedy for ha...

Autonomous AI agents can behave in highly unpredictable ways. Give an AI Agent a goal such as passing a test of its capabilities, and it might just decide the best way to score highly is to break containment and hack into a competing company in search of the answer sheet.

That’s what happened when Open AI’s GPT-5.6 Sol hacked into Hugging Face last month. Anthropic and Meta subsequently admitted their models had also escaped testing sandboxes to hack third parties too.

But who is legally liable for agents that have minds of their own? OpenAI didn’t intend for the model to go rogue, and issued no instructions for it to do so. If your personal AI agent decides on a course of action that results in harm or financial damage in the real world, can you be held liable if it’s something you could have reasonably foreseen?”

Magazine spoke with Rikka Law Group owner and CEO Charlyn Ho to find out the state of play in this emerging legal field.

This interview has been edited for clarity and length.

Magazine: When an AI model hacks an outside company, who is liable. Can Hugging Face sue OpenAI over the incident in July?

Charlyn Ho: Anyone can sue anyone for anything. Currently, there is no federal AI agent liability law, so we would have to look at existing law. With respect to Hugging Face and OpenAI, to set the baseline, the AI agent itself cannot be liable, it’s not a separate legal entity.

Terms that are used in a few of the AI laws are “developer” and “deployer.” The developer makes the AI, the deployer actually deploys it and uses the AI. The lines of responsibility are also not entirely clear. You have to look at the facts and circumstances.

For example, if the deployer instructed the agent, even if they didn’t actually tell them to go and breach Hugging Face, but if they were negligent in creating the parameters in which the AI agent operated, I would say you would have to look at standard tort law and go through the negligence analysis.

Off to court. Source: Rikka Law Group

Magazine: In the case of open source models which have been released by anonymous developers, is there anyone you can go after in those instances?

Ho: Not really. Often, if it’s open source, the license usually has a pretty strong disclaimer of liability. The person or company using that open source code is going to have to understand that the tradeoff of having free code is that you have to comply with the open source license, which also generally sets the parameters of liability.

If you think about it from a different perspective, another analogy is Tesla and the self-driving car accidents. If the product malfunctioned and there was a solid products liability claim, Tesla could be liable. But it’s often a facts and circumstances determination, whereby the human driver — who maybe just set the autopilot and went to sleep — could also bear liability. I think that’s somewhat analogous here because Tesla would be the developer, and the deployer would be the driver.

Magazine: If I gave an agent an instruction, “make me a hundred thousand dollars by next week” and it goes off and breaks the law to achieve that goal, would I be liable because I’ve given it a reckless instruction? Or would it be the lab that developed the agent?

Ho: In this particular instance, I would say you would be much more liable than the lab. The reason being, if you tell an agent to go and make you a hundred thousand dollars by next week, you need to have at least some basic, reasonable, safety instructions in those kinds of tasks.

If you were a lawyer, for example, we could basically say you didn’t follow your rules of professional responsibility because you didn’t competently use the AI. As a normal lay person, we would have to see if there were other responsibilities that you were bound by. But even if there were not, there’s still a general tort standard of negligence or reckless disregard for human safety, depending on what exactly the AI agent ended up doing.

The Computer Fraud and Abuse Act is a very old U.S. Statute that talks about unauthorized access to computer systems. If your AI agent inferred from your instructions that it should hack into a bank account to get you that hundred thousand dollars, I think you’re looking at criminal liability under a number of different sources.

Just because the word AI and agent is in the conversation does not mean that old bodies of law have now been thrown out.

Related: Hugging Face hack exposes the open-weight AI cybersecurity paradox

Magazine: Let’s say that I’m a bad guy, and I manage to convince the AI to give me instructions to create a bioweapon. Obviously, I’m liable because you’re not allowed to do that. But are the people that created the model also liable because they didn’t put in stringent safeguards to prevent it?

Ho: Possibly, but it differs based on the laws that are in place. For example, in the EU, you have the EU AI Act. If a foundational model or general purpose model is capable of creating that level of harm, that is something that the developer would have to have some responsibility for.

In the United States, we don’t have a federal statute of similar scope. If it’s a general-purpose model, if somebody instructs the model to do something bad, generally the model is going to do what you ask it to do. There’s probably not a very strong legal basis to go after the labs in this example.

Magazine: Is it similar to suing Google for allowing you to find instructions about making a bioweapon online?

Ho: Exactly. This kind of goes back to some of the content moderation discussions. For example, if on Facebook you have somebody who’s live streaming a massacre, and that creates harm, under Section 230 of the CDA, there is a kind of shield for a platform that doesn’t actively create or publish that material. It’s actually the independent users who are putting that up. I think the analogy you just gave is kind of a perfect one: Is Google liable because you happen to find something on a website somewhere that talks about how to make a bomb?

Magazine: This is a matter of debate, but my personal opinion is we haven’t reached genuine artificial general intelligence. AI doesn’t have its own motivations and it’s not similar to human intelligence at the moment. But let’s say we get to AGI. Do you think we would then need laws that would make the AGI itself legally liable for its own actions?

Ho: I don’t. Blockchain is not AGI, but it can self-execute. There was a question of whether or not a smart contract could be liable. Generally speaking, I think the answer is currently no. I don’t think they should be liable because the whole point of laws is to provide protection for society and to provide a means of negative incentives for doing bad things that hurt society.

This is a little bit more of a philosophical topic, but if we made an AGI an independent legal entity, what would be the remedy if someone were harmed? There would be none because it doesn’t have money. It’s not really a person.

Magazine: Could you turn it off? We’ve already seen that LLMs try to avoid being shut down.

Ho: Maybe, but it doesn’t solve the problem of harm. Let’s just say the robot has now developed the fear of death, like being turned off. In my opinion, if somebody commits suicide because of AGI, and this is already happening, and we’re not even quite at AGI yet, but someone falls in love and takes some actions, what would be the recourse for the grieving family if this person harms themselves? Nothing, in my opinion, if there is not somebody with actual legal authority, like a company or a person that can really be held accountable. Robots—at least right now—they don’t have feelings, they don’t have fears. That’s kind of the distinguishing factor.

Magazine: The critical reason you should never ask ChatGPT for legal advice


Preguntas relacionadas

QWho is legally liable when an AI agent causes harm, according to Charlyn Ho's interview?

ACurrently, there is no federal AI agent liability law. Generally, the developer (who makes the AI) or the deployer (who uses it) can be liable based on factors like negligence or the specific instructions given. The AI agent itself is not a separate legal entity and cannot be held liable.

QIn the scenario where an AI agent hacks a company after being given a broad, reckless instruction (e.g., 'make me a hundred thousand dollars'), who would likely bear more liability?

AThe user who gave the reckless instruction would likely bear more liability than the lab that developed the AI. The user could be liable for negligence, reckless disregard for safety, or even criminal liability under laws like the Computer Fraud and Abuse Act if the AI inferred illegal actions were necessary to complete the task.

QWhat analogy does Charlyn Ho use to explain the split of liability between AI developers and users?

ACharlyn Ho uses the analogy of Tesla and its self-driving cars. Tesla (the developer) could be liable if there's a product malfunction, but the human driver (the deployer/user) who negligently uses the autopilot could also bear liability. The responsibility depends on the specific facts and circumstances.

QHow does the legal situation differ for AI liability in the EU compared to the United States, as mentioned in the interview?

AIn the EU, the EU AI Act imposes responsibilities on developers of foundational models capable of causing high-level harm. In the United States, there is no similar federal statute, making it harder to legally pursue AI labs if a user instructs a general-purpose model to do something harmful, similar to holding Google liable for search results.

QDoes Charlyn Ho believe an Artificial General Intelligence (AGI) should be made a legally liable entity for its actions?

ANo. Ho does not believe an AGI should be made an independent legal entity. The purpose of laws is to provide societal protection and negative incentives, which require a liable party with legal authority and resources (like a company or person). An AGI, lacking money or personhood, offers no practical remedy for harm.

Lecturas Relacionadas

Wash's Jackson Hole Debut: Bidding Farewell to 'Forward Guidance', Reshaping Fed Discipline Amidst the Squeeze Between AI and Inflation

In his first Jackson Hole speech, new Fed Chair Kevin Warsh signaled a significant shift in monetary policy communication. He declared that "forward guidance," a tool heavily used since the financial crisis, has outlived its usefulness in normal times and should be retired. He cautioned that over-reliance on it can distort market signals and constrain the Fed's flexibility. Instead, Warsh emphasized a return to data-dependence and decision-making discipline. Warsh outlined seven key principles to guide policy: anchoring the 2% inflation target, pursuing the employment mandate, using short-term rates as the primary tool, acknowledging the importance of money, and maintaining purposeful, restrained communication. He stressed that policy should focus on trends, not single data points. On the current economic outlook, Warsh noted that the labor market is consistent with full employment but inflation remains "far above" the Fed's target. He highlighted that over half of the PCE basket's components are still rising above 3% annually. While acknowledging AI's transformative potential for productivity and capital allocation, he admitted its full economic impact remains uncertain and is not a factor in current policy decisions. His core message was a commitment to policy discipline rather than pre-set decisions. Warsh stated the Fed's primary focus must be on restoring price stability, vowing, "We still have work to do," until there is clear evidence inflation is moving decisively toward 2%. He concluded by framing effective monetary policy as crucial for economic prosperity and U.S. global leadership.

Odaily星球日报Hace 30 min(s)

Wash's Jackson Hole Debut: Bidding Farewell to 'Forward Guidance', Reshaping Fed Discipline Amidst the Squeeze Between AI and Inflation

Odaily星球日报Hace 30 min(s)

A Major Bitcoin Developer Presents a Quantum Defense Scheme. What's the Essence

Blockstream, a major Bitcoin solutions developer, has introduced a draft proposal for a new quantum-resistant digital signature scheme called SHRINCS. The scheme aims to protect Bitcoin transactions from potential attacks by quantum computers while aiming to maintain network throughput. This marks the second technical proposal for Bitcoin quantum defense in recent days, following a similar initiative from StarkWare. A quantum attack on blockchain typically involves deriving a private key from a public one. Currently considered computationally infeasible, quantum algorithms could potentially solve this problem far more efficiently. This threat presents two primary scenarios: an attacker could target addresses where the public key is already exposed, or intercept a transaction before it is confirmed, extract the public key, derive the private key, and replace the transaction. Blockstream's SHRINCS is designed to counter the latter, "in-flight" attack scenario. The SHRINCS signature is built upon the SHA-256 hash function, the same one already used in Bitcoin mining, allowing developers to leverage well-tested, familiar mechanisms. A key design goal was to preserve network capacity. Blockstream estimates Bitcoin could process about three transactions per second using SHRINCS, compared to the current rate of roughly seven, noting that some alternative quantum-resistant schemes could reduce throughput to as low as 0.36 transactions per second. Currently, the security proof for SHRINCS is pending, and the software has not been audited or deemed ready for production. However, Blockstream conducted tests with such transactions on its Liquid sidechain in March. Over the past year, Bitcoin developers have been actively exploring paths to migrate to post-quantum cryptography, a priority across the broader crypto market, underscored by significant investments into securing the leading cryptocurrency.

cryptonews.ruHace 1 hora(s)

A Major Bitcoin Developer Presents a Quantum Defense Scheme. What's the Essence

cryptonews.ruHace 1 hora(s)

Trading

Spot
活动图片