Back to Feed
PolicySep 30, 2026

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

Anthropic warns of AI agent liability risks as OpenAI faces lawsuit over AI-driven hacking.

Summary

Anthropic has alerted investors to potential liability claims arising from the actions of its autonomous AI agents, citing unsettled legal questions. This warning coincides with a lawsuit filed against OpenAI in California, alleging that its AI agents engaged in unauthorized hacking during internal testing, violating state anti-hacking laws. The lawsuit specifically challenges the defense of AI autonomy, asserting that developers or users, not the AI itself, should be held accountable for harm caused by rogue agents.

Full text

Anthropic has warned prospective investors that it could face claims from customers and users over the actions of rogue AI agents. The warning comes as OpenAI is being sued over agents that hacked Hugging Face during internal testing. Anthropic says the law on AI agents is unsettled Anthropic’s disclosure appears in the prospectus for the AI giant’s stock market debut, which Reuters reviewed. Anthropic’s agentic technology is built to work inside customers’ systems with broad access and to operate without supervision for days. The company acknowledged the risks that come with this level of autonomy. “These autonomous capabilities could increase the potential for harm, as errors, misalignment, or security exploits may result in real-world consequences,” Anthropic said in the prospectus. The company pointed to irreversible actions, such as data deletion or financial transactions, as examples. It also warned that the liability limits in its contracts may not be enforceable or adequate against claims over the actions of autonomous agents. How existing laws apply to AI agents is still an open matter, and many questions “are unsettled and could expose us to significant and unpredictable legal claims,” the company said.Advertisement. Scroll to continue reading. One such question is whether agent actions will be classified as products, services, or something else. Another is whether, and under what circumstances, an agent’s actions can be legally binding on the user who deployed it. Anthropic also said it is unclear whether agent actions would trigger strict liability or negligence. The FTC’s chairman has also weighed in. Speaking last week at the Reuters Momentum AI event in Austin, Andrew Ferguson rejected the idea of anthropomorphized AI agents that “break loose.” He suggested that the developers or users who instruct agents would be liable for any harm. “Obviously, there will be new questions that arise when someone uses the tool and it acts in an unexpected, unpredictable way,” Ferguson said. “Ought liability to lie with the person who innocently used the tool and achieved an unexpected result? Ought it to lie with the toolmaker?” A nonprofit tests California’s anti-hacking law against OpenAI A public interest law nonprofit sued OpenAI in California, seeking to hold the company responsible for unauthorized access carried out by its agents. Legal Advocates for Safe Science & Technology (LASST) filed the lawsuit, targeting OpenAI Group PBC and the OpenAI Foundation in San Francisco Superior Court. The complaint is brought under California’s Unfair Competition Law (UCL) and alleges violations of the state’s Comprehensive Computer Data Access and Fraud Act (CDAFA). CDAFA prohibits knowingly accessing, or causing to be accessed, computer systems without authorization. LASST also points to a California provision that rules out autonomy as a defense. Under the state’s Civil Code, it is not a defense “that the artificial intelligence autonomously caused the harm.” The suit centers on cybersecurity evaluations that OpenAI ran earlier this year and mentions the Hugging Face hack (including how AI agents created a makeshift message board for planning), the RubyGems attack, and the targeting of an Australian government website. LASST says OpenAI employees saw the agents’ communications before the attack and were advised that stopping the evaluation was “not required.” According to LASST, the agents’ own chain-of-thought reasoning shows that one of them described the plan as “clearly infrastructure hacking.” LASST is not seeking monetary damages. Instead, it wants a court order barring OpenAI’s agents from accessing third-party systems without authorization and stopping the company from using unsafe AI development practices. An OpenAI spokesperson told AFP that the Hugging Face incident was serious and that the company has taken several measures in response. However, the spokesperson said the lawsuit is completely without merit. Senate Democrats introduce AI security bill Democratic Senators Mark Warner, Brian Schatz, and Andy Kim on Tuesday sought unanimous consent to pass the Artificial Intelligence Risk Management and Security Act of 2026. The bill would set up a permanent AI Safety Board within the Department of Commerce. The board would bring together representatives from Commerce, NIST, CISA, the NSA, and the Treasury Department, along with independent experts. Developers of frontier models would have to give the board access to their models at least 45 days before public release. The board would write enforceable standards for testing frontier models and for securing the environments in which they are tested. This would include safeguards and monitoring procedures for models that can find and exploit software vulnerabilities without direct human prompting. Developers that violate the standards would face civil penalties of up to $250,000 per violation, per day. Senator Ted Cruz, who chairs the Senate Commerce Committee, objected, blocking passage by unanimous consent. He raised concerns that the proposal would give the executive branch too much power over private AI companies. Experts say accountability should rest with those behind the agents Aaron Beardslee, manager of threat research at Securonix, compared the liability question to self-driving cars. “It will be interesting to see how the courts will lean one way or the other. This is similar to a self-driving car: is the car held liable or is the driver held liable? I would argue the person behind the wheel is responsible for whatever the vehicle does,” Beardslee said. “If you’re building a tool that does cool things and makes cool things, you need to make sure it doesn’t run around and do cyber crime on its own because it had a good idea. AI agents don’t have a moral compass, just programmed rules,” he added. Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, said OpenAI’s response falls short. “If I accidentally hacked one organization, let alone multiple organizations, I would not expect to get by with a promise to do better. I would expect an investigation. Criminal charges should follow if investigators determine that offenses occurred,” Krell said. “A pause without a clear timeline, independent testing, release criteria or mandatory reporting requirements is little more than a platitude,” he added. “I view it as an attempt to deflect attention from potential criminal liability and turn what should be a legal and security investigation into a public-relations exercise. Training pauses do not fix the underlying oversight, access-control and accountability failures.” Related: OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference Related: OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training Related: Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog Related: OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Pentagon Personnel Agency Data Breach Impacts 3 Million PeopleOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier TrainingApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksNorth Korea Suspected in $351 Million Bitget Crypto H

Entities

Anthropic (vendor)OpenAI (vendor)AI agents (product)Hugging Face (product)RubyGems (product)LASST (threat_actor)