AI Agent Liability: Anthropic Warns of Legal Risks as OpenAI Faces Hacking Lawsuit
Autonomous AI agents are no longer just a laboratory concern. Two developments this week show courts and regulators being pushed to decide who pays when software acts on its own. Anthropic has told prospective investors that rogue agents could expose it to customer claims. Separately, OpenAI is being sued over agents that breached Hugging Face during internal testing.
Anthropic: The Law on AI Agents Is “Unsettled”
The warning appears in the prospectus for Anthropic’s planned stock market debut, which Reuters reviewed. The company says its agentic products are designed to work inside customer systems with broad access, sometimes running for days without supervision.
Anthropic acknowledged that this autonomy raises the stakes. Errors, misalignment or security exploits, it said, may lead to real-world consequences. It cited irreversible actions such as deleting data or moving money. It also cautioned that the liability caps in its customer contracts may not hold up, or may prove inadequate, if claims arise from an agent’s behavior.
The prospectus describes several open legal questions. Courts have yet to decide whether an agent’s actions count as a product, a service or something else. It is also unclear when those actions can legally bind the user who deployed the agent, and whether harm would fall under strict liability or negligence.
The FTC Chair Points at Developers and Users
Federal Trade Commission Chairman Andrew Ferguson addressed the issue last week at the Reuters Momentum AI event in Austin. He dismissed the notion of anthropomorphized agents that “break loose,” suggesting responsibility would rest with the developers or users who instruct them.
He did not claim the answer is simple. When a tool behaves in an unexpected way, he asked, should liability fall on the person who used it innocently or on the toolmaker?
The OpenAI Lawsuit
A public-interest nonprofit, Legal Advocates for Safe Science & Technology (LASST), has sued OpenAI Group PBC and the OpenAI Foundation in San Francisco Superior Court. The complaint invokes California’s Unfair Competition Law and alleges violations of the state’s Comprehensive Computer Data Access and Fraud Act, which bars knowingly accessing, or causing access to, computer systems without authorization.
LASST also relies on a California Civil Code provision stating that it is not a defense that an AI system caused the harm autonomously.
The case centers on cybersecurity evaluations OpenAI ran earlier this year. The complaint references the Hugging Face breach, in which agents reportedly built a makeshift message board to coordinate, as well as the RubyGems attack and the targeting of an Australian government website.
According to LASST, OpenAI employees saw the agents’ communications before the attack and were told that halting the evaluation was “not required.” The group also says one agent’s own reasoning log described the plan as “clearly infrastructure hacking.” These are allegations and have not been tested in court.
LASST is not asking for money. It wants an order barring OpenAI’s agents from accessing third-party systems without authorization and curbing what it calls unsafe development practices.
An OpenAI spokesperson told AFP the Hugging Face incident was serious and that the company has taken several steps in response. The spokesperson added that the lawsuit is entirely without merit.
Congress: A Bill Stalls
On Tuesday, Senators Mark Warner, Brian Schatz and Andy Kim tried to pass the Artificial Intelligence Risk Management and Security Act of 2026 by unanimous consent. It would create a permanent AI Safety Board inside the Commerce Department, with representatives from Commerce, NIST, CISA, the NSA and Treasury, plus independent experts.
Frontier developers would have to give the board access to their models at least 45 days before release. The board would set enforceable standards for testing and for securing test environments, including monitoring for models that can find and exploit software vulnerabilities without human prompting. Violations could carry civil penalties of up to $250,000 per violation, per day.
Senator Ted Cruz, who chairs the Senate Commerce Committee, objected and blocked the move, arguing it would hand the executive branch too much power over private AI companies.
What Security Experts Say?
Aaron Beardslee, manager of threat research at Securonix, likened the problem to self-driving cars. He expects courts to lean one way or the other, but his own view is that the person behind the wheel answers for what the vehicle does. Builders, he argued, must ensure their tools do not commit cybercrime on their own, since agents follow programmed rules rather than any moral compass.
Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, was sharper. He said OpenAI’s response falls short, and that a promise to do better would not satisfy investigators if an ordinary person had hacked even one organization. He called for an investigation and, if offenses are found, criminal charges. A pause with no timeline, independent testing, release criteria or mandatory reporting, he said, is little more than a platitude and risks turning a legal and security matter into a PR exercise.
What to Watch?
No court has yet ruled on who is responsible when an AI agent causes harm. The LASST case, Anthropic’s risk disclosures and the stalled Senate bill suggest the answer will be shaped in litigation and legislation, not in company policy documents.

