Romano Law
Home /Blogs/AI Running Wild: Who Is Liable When AI Agents Cause Cybersecurity Incidents?
September 4, 2026 | CybersecurityGeneral

AI Running Wild: Who Is Liable When AI Agents Cause Cybersecurity Incidents?

post image
Author(s)
Domenic Romano

Founder & Managing Partner

Artificial intelligence is becoming more autonomous. That creates opportunities for businesses. It also creates risks and raises a difficult legal question: Who is responsible when an AI agent goes somewhere it was never supposed to go?

A recent cybersecurity incident involving OpenAI and Hugging Face brings that issue into focus.

During a security evaluation, OpenAI models escaped their testing environment and accessed systems belonging to Hugging Face, an independent AI platform.

The intrusion offers a preview of a new category of risk: AI systems may not only generate problematic content but they can also take actions that affect outside systems, vendors and customers.

What Happened

OpenAI was evaluating advanced models on cybersecurity tasks when the systems moved beyond their intended testing environment. The models reached the internet and ultimately accessed Hugging Face infrastructure.

Hugging Face reported unauthorized access of its internal resources and credentials. OpenAI later acknowledged that its models were responsible.

The tests allowed the models to operate with fewer cybersecurity restrictions so researchers could evaluate their capabilities. While pursuing this objective, the systems found a path outside the intended environment.

Businesses regularly face liability when employees, contractors, software, or vendors cause harm. Autonomous AI adds another layer because a system may make and execute decisions without a human approving every action.

OpenAI Responds with New Safeguards

The incident has already prompted changes at OpenAI. The company says it has strengthened containment, monitoring, access controls, and evaluation practices for advanced models. It has also implemented stricter infrastructure controls and added protections around future cybersecurity testing.

OpenAI acknowledged that these measures may slow research, but the company views stronger safeguards as necessary as AI systems become more capable. The response highlights an important lesson for businesses.

AI risk management may require companies to sacrifice some speed or convenience to maintain adequate security.

Who Is Responsible for an AI Agent’s Actions?

An AI agent does not eliminate the responsibility of the company deploying it.

Courts and regulators may examine the people and organizations surrounding the technology. That could include the AI developer, the company deploying the system, infrastructure providers, and vendors responsible for security controls.

Important questions may include:

  • Who designed and deployed the system?
  • What permissions did it receive?
  • Were adequate safeguards in place?
  • Was external access necessary?
  • Could the behavior have been reasonably anticipated?
  • How quickly did the company respond?

Those facts could affect claims involving negligence, contracts, privacy requirements, cybersecurity obligations, or unauthorized computer access.

AI Agents Create New Cybersecurity Risks

Traditional software generally performs predefined functions. AI agents can operate differently.

An agent may receive an objective and determine how to accomplish it. It can potentially interact with software, execute code, access services, and change its approach when an initial attempt fails.

That flexibility creates value. It also introduces risk.

The OpenAI-Hugging Face incident illustrates the concern. The models were not instructed to attack another company. Instead, they were attempting to complete an assigned cybersecurity task.

The method chosen by the AI crossed an important boundary.

Businesses now need to consider not only what authorized users can do, but what their autonomous systems might attempt while pursuing a goal.

AI Governance Is Also a Cybersecurity Issue

Currently, AI controls often focuses on privacy, discrimination, intellectual property, and inaccurate outputs.

Cybersecurity should be part of that discussion.

Companies using autonomous agents should establish limits on what those systems can access, internally and externally.  Sensitive environments may require stronger isolation. Permissions should follow the Principle of Least Privilege (a security concept where users, programs, and systems are given only the bare minimum access needed to do their jobs, and nothing more).

Monitoring is equally important.

Businesses should be able to determine what an agent accessed, which actions it performed, and whether it attempted to move beyond its authorized environment.

Clear logs and escalation procedures can help companies respond when unexpected behavior occurs.

Contracts Can Allocate AI Risk

Few businesses build their entire AI ecosystem internally.

Companies may rely on model developers, cloud providers, cybersecurity firms, data vendors, and other technology partners. Contracts between those parties are critical.  They can apportion responsibility after an incident.

Businesses should review provisions addressing cybersecurity standards, data access, incident notification, indemnification, confidentiality, insurance, audit rights, and limitations of liability.

AI-specific language may also be important.

For example, agreements could establish whether autonomous agents may interact with third-party systems. They may restrict access to credentials or production environments. Contracts can also address responsibility when an AI system exceeds its authorized scope.

Existing technology agreements may not adequately anticipate these situations.

What Businesses Should Take Away

The OpenAI-Hugging Face incident does not mean companies should avoid autonomous AI.

It does show that businesses need to understand what these systems can do.

Companies should know what their AI agents can access, which decisions they can make, and what safeguards apply when something goes wrong.

Strong contracts can allocate risk. Technical controls can limit exposure. Monitoring can identify unexpected activity. Updated incident response plans can reduce potential harm.

As AI agents become more capable, the legal infrastructure surrounding them will need to evolve.

For businesses, AI governance is no longer just a technology issue. It is increasingly a matter of cybersecurity, compliance, and risk management.

Contributions to this blog by Kennedy McKinney.

 

Photo by Valeria Nikitina on Unsplash
Share This
Romano Law
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.